#19197 [Opn]: Serious bug with ImageCreateTrueColor and/or ? file upload
| From: | bugsphp at yayel dot com | Date: | Tue, 03 Sep 2002 21:14:17 +0000 |
| Subject: | #19197 [Opn]: Serious bug with ImageCreateTrueColor and/or ? file upload | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-18335@lists.php.net to get a copy of this message | ||
ID: 19197
User updated by: bugsphp@yayel.com
Reported By: bugsphp@yayel.com
Status: Open
Bug Type: GD related
Operating System: Linux Redhat 7.2
PHP Version: 4.2.2
New Comment:
Wow, it's been I while I could not reach bugs.php.net...
anyway, I solve my problem and also tried to submit my comment to
imagecreatetruecolor documentation page.
When you think about it (and I was stupid), a Gif can't be made with
ImageCreateTrueColor() since it can only index 256 colors.
BUT: the problem still remains, there is no warning or an error message
when ImageGif() is used with ImageCreateTrueColor(), and php crashed
instead (and it's really a dirty bug, according that my script loops
till it ends with apache child process).
Thank you for fixing it.
Previous Comments:
------------------------------------------------------------------------
[2002-08-30 17:22:03] bugsphp@yayel.com
Starting program: /usr/local/apache/bin/httpd -X
Program received signal SIGSEGV, Segmentation fault.
0x082318fb in compress (init_bits=3, outfile=0x83c5a98, im=0x83ec238)
at gd_lzw_out.c:534
534 if ( HashTabOf (i) == fcode ) {
(gdb) bt
#0 0x082318fb in compress (init_bits=3, outfile=0x83c5a98,
im=0x83ec238) at gd_lzw_out.c:534
#1 0x0823178e in GIFEncode (fp=0x83c5a98, GWidth=100, GHeight=35,
GInterlace=0, Background=0, Transparent=-1,
BitsPerPixel=1, Red=0x83ec248, Green=0x83ec648, Blue=0x83eca48,
im=0x83ec238) at gd_lzw_out.c:349
#2 0x08231237 in gdImageLzwCtx (im=0x83ec238, out=0x83c5a98) at
gd_lzw_out.c:67
#3 0x0823117c in gdImageGifCtx (im=0x83ec238, out=0x83c5a98) at
gd_gif_out.c:23
#4 0x080b50aa in _php_image_output_ctx (ht=2, return_value=0x83dac3c,
this_ptr=0x0, return_value_used=0,
image_type=1, tn=0x8243caf "GIF", func_p=0x8231168 <gdImageGifCtx>)
at gd_ctx.c:94
#5 0x080b91be in zif_imagegif (ht=2, return_value=0x83dac3c,
this_ptr=0x0, return_value_used=0) at gd.c:1462
#6 0x081a67f3 in execute (op_array=0x83c1804) at
./zend_execute.c:1598
#7 0x08182c96 in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at zend.c:810
#8 0x0809b0d2 in php_execute_script (primary_file=0xbffff730) at
main.c:1381
#9 0x0818e2f6 in apache_php_module_main (r=0x8358814,
display_source_mode=0) at sapi_apache.c:90
#10 0x080974b4 in send_php () at eval.c:41
#11 0x0809750d in send_parsed_php () at eval.c:41
#12 0x081b067b in ap_invoke_handler () at eval.c:41
#13 0x081c5243 in process_request_internal () at eval.c:41
#14 0x081c52a4 in ap_process_request () at eval.c:41
#15 0x081bc24d in child_main () at eval.c:41
#16 0x081bc3f8 in make_child () at eval.c:41
#17 0x081bc56c in startup_children () at eval.c:41
#18 0x081bcbe8 in standalone_main () at eval.c:41
#19 0x081bd457 in main () at eval.c:41
#20 0x4031e306 in __libc_start_main (main=0x81bd0a8 <main>, argc=2,
ubp_av=0xbffffb64, init=0x8074b50 <_init>,
fini=0x8237c40 <_fini>, rtld_fini=0x4000d2dc <_dl_fini>,
stack_end=0xbffffb5c)
at ../sysdeps/generic/libc-start.c:129
Ok, gif IS the problem.
I'm not a C guru, but I can't understand why is there so many mysql
inserts and file copies because of the buggy gd function... Again I
don't know anything about C :)
Thank you for your help and fixes !!
------------------------------------------------------------------------
[2002-08-30 11:16:32] sander@php.net
See http://bugs.php.net/bugs-generating-backtrace.php.
BTW, you might want to try the bundled version of GD2 in PHP 4.3.0-dev.
Grab a (non-STABLE) snapshot from http://snaps.php.net.
------------------------------------------------------------------------
[2002-08-30 11:11:27] cynic@php.net
imo it's quite obvious which parts of the script are irrelevant:
input checking, database stuff, jpeg/png/... stuff.
as for the backtrace: that's described in the page you should've read
before submiting: http://bugs.php.net/how-to-report.php
------------------------------------------------------------------------
[2002-08-30 11:07:48] bugsphp@yayel.com
Apache reports several times in error_log strings like that one: [Fri
Aug 30 17:00:17 2002] [notice] child pid 29648 exit signal Segmentation
fault (11)
------------------------------------------------------------------------
[2002-08-30 11:05:19] bugsphp@yayel.com
Sorry Cynic, I don't really have a debugging experience.
I did not know what to cut (that's why code is not published here), but
know that everything gets ok if ImageCreateTrueColor() (line 91) is
replaced by ImageCreate().
I'll rebuild php, please tell me how to find the backtrace.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/19197
--
Edit this bug report at http://bugs.php.net/?id=19197&edit=1