Sec Bug->Bug #66356 [Csd]: Heap Overflow Vulnerability in imagecrop()
| From: | remi@php.net | Date: | Wed, 12 Feb 2014 16:40:58 +0000 |
| Subject: | Sec Bug->Bug #66356 [Csd]: Heap Overflow Vulnerability in imagecrop() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184273@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66356&edit=1
ID: 66356
Updated by: remi@php.net
Reported by: kuba dot brecka at gmail dot com
Summary: Heap Overflow Vulnerability in imagecrop()
Status: Closed
-Type: Security
+Type: Bug
Package: GD related
Operating System: all
PHP Version: 5.5.7
Assigned To: pajoye
Block user comment: N
Private report: Y
New Comment:
Drop the security type as 5.5.9 is now released.
Previous Comments:
------------------------------------------------------------------------
[2013-12-28 21:07:41] kuba dot brecka at gmail dot com
Please use CVE-2013-7226 for this issue.
------------------------------------------------------------------------
[2013-12-28 13:33:51] remi@php.net
@laruence, I think it could make sense to apply your check in the PHP side...
------------------------------------------------------------------------
[2013-12-28 13:31:05] remi@php.net
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
See http://git.php.net/?p=php-src.git;a=commitdiff;h=8f4a5373bb71590352fd934028d6dde5bc18530b
------------------------------------------------------------------------
[2013-12-28 09:45:19] pajoye@php.net
@remi Please sync with gd 2.1.x tree isntead, there are all bug fixes in it and no new features.
------------------------------------------------------------------------
[2013-12-28 08:20:56] remi@php.net
2 patches proposal (tested on php 5.5)
v1: position out of src image will return NULL.
v2: position out of the src image, will return a blank image, which is consistent with current size
check: As the size check is done "after" image allocation, so, result image could be
partially blank, but always of requested size.
We could also think of moving size check "before" allocation, but this will be a BC
break.
New size check seems better (even if the test is not really readable) and should be integer overflow
free.
For PHP 5.6, I will prefer to see bundled libgd updated to upstream version 2.1.x
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=66356
--
Edit this bug report at https://bugs.php.net/bug.php?id=66356&edit=1