#19197 [Opn]: Serious bug with ImageCreateTrueColor and/or ? file upload

From: Date: Tue, 03 Sep 2002 21:14:17 +0000
Subject: #19197 [Opn]: Serious bug with ImageCreateTrueColor and/or ? file upload
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-18335@lists.php.net to get a copy of this message
ID: 19197 User updated by: bugsphp@yayel.com Reported By: bugsphp@yayel.com Status: Open Bug Type: GD related Operating System: Linux Redhat 7.2 PHP Version: 4.2.2 New Comment: Wow, it's been I while I could not reach bugs.php.net... anyway, I solve my problem and also tried to submit my comment to imagecreatetruecolor documentation page. When you think about it (and I was stupid), a Gif can't be made with ImageCreateTrueColor() since it can only index 256 colors. BUT: the problem still remains, there is no warning or an error message when ImageGif() is used with ImageCreateTrueColor(), and php crashed instead (and it's really a dirty bug, according that my script loops till it ends with apache child process). Thank you for fixing it. Previous Comments: ------------------------------------------------------------------------ [2002-08-30 17:22:03] bugsphp@yayel.com Starting program: /usr/local/apache/bin/httpd -X Program received signal SIGSEGV, Segmentation fault. 0x082318fb in compress (init_bits=3, outfile=0x83c5a98, im=0x83ec238) at gd_lzw_out.c:534 534 if ( HashTabOf (i) == fcode ) { (gdb) bt #0 0x082318fb in compress (init_bits=3, outfile=0x83c5a98, im=0x83ec238) at gd_lzw_out.c:534 #1 0x0823178e in GIFEncode (fp=0x83c5a98, GWidth=100, GHeight=35, GInterlace=0, Background=0, Transparent=-1, BitsPerPixel=1, Red=0x83ec248, Green=0x83ec648, Blue=0x83eca48, im=0x83ec238) at gd_lzw_out.c:349 #2 0x08231237 in gdImageLzwCtx (im=0x83ec238, out=0x83c5a98) at gd_lzw_out.c:67 #3 0x0823117c in gdImageGifCtx (im=0x83ec238, out=0x83c5a98) at gd_gif_out.c:23 #4 0x080b50aa in _php_image_output_ctx (ht=2, return_value=0x83dac3c, this_ptr=0x0, return_value_used=0, image_type=1, tn=0x8243caf "GIF", func_p=0x8231168 <gdImageGifCtx>) at gd_ctx.c:94 #5 0x080b91be in zif_imagegif (ht=2, return_value=0x83dac3c, this_ptr=0x0, return_value_used=0) at gd.c:1462 #6 0x081a67f3 in execute (op_array=0x83c1804) at ./zend_execute.c:1598 #7 0x08182c96 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at zend.c:810 #8 0x0809b0d2 in php_execute_script (primary_file=0xbffff730) at main.c:1381 #9 0x0818e2f6 in apache_php_module_main (r=0x8358814, display_source_mode=0) at sapi_apache.c:90 #10 0x080974b4 in send_php () at eval.c:41 #11 0x0809750d in send_parsed_php () at eval.c:41 #12 0x081b067b in ap_invoke_handler () at eval.c:41 #13 0x081c5243 in process_request_internal () at eval.c:41 #14 0x081c52a4 in ap_process_request () at eval.c:41 #15 0x081bc24d in child_main () at eval.c:41 #16 0x081bc3f8 in make_child () at eval.c:41 #17 0x081bc56c in startup_children () at eval.c:41 #18 0x081bcbe8 in standalone_main () at eval.c:41 #19 0x081bd457 in main () at eval.c:41 #20 0x4031e306 in __libc_start_main (main=0x81bd0a8 <main>, argc=2, ubp_av=0xbffffb64, init=0x8074b50 <_init>, fini=0x8237c40 <_fini>, rtld_fini=0x4000d2dc <_dl_fini>, stack_end=0xbffffb5c) at ../sysdeps/generic/libc-start.c:129 Ok, gif IS the problem. I'm not a C guru, but I can't understand why is there so many mysql inserts and file copies because of the buggy gd function... Again I don't know anything about C :) Thank you for your help and fixes !! ------------------------------------------------------------------------ [2002-08-30 11:16:32] sander@php.net See http://bugs.php.net/bugs-generating-backtrace.php. BTW, you might want to try the bundled version of GD2 in PHP 4.3.0-dev. Grab a (non-STABLE) snapshot from http://snaps.php.net. ------------------------------------------------------------------------ [2002-08-30 11:11:27] cynic@php.net imo it's quite obvious which parts of the script are irrelevant: input checking, database stuff, jpeg/png/... stuff. as for the backtrace: that's described in the page you should've read before submiting: http://bugs.php.net/how-to-report.php ------------------------------------------------------------------------ [2002-08-30 11:07:48] bugsphp@yayel.com Apache reports several times in error_log strings like that one: [Fri Aug 30 17:00:17 2002] [notice] child pid 29648 exit signal Segmentation fault (11) ------------------------------------------------------------------------ [2002-08-30 11:05:19] bugsphp@yayel.com Sorry Cynic, I don't really have a debugging experience. I did not know what to cut (that's why code is not published here), but know that everything gets ok if ImageCreateTrueColor() (line 91) is replaced by ImageCreate(). I'll rebuild php, please tell me how to find the backtrace. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/19197 -- Edit this bug report at http://bugs.php.net/?id=19197&edit=1

« previous php.bugs (#18335) next »