Sec Bug->Bug #66356 [Csd]: Heap Overflow Vulnerability in imagecrop()

From: Date: Wed, 12 Feb 2014 16:40:58 +0000
Subject: Sec Bug->Bug #66356 [Csd]: Heap Overflow Vulnerability in imagecrop()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184273@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66356&edit=1 ID: 66356 Updated by: remi@php.net Reported by: kuba dot brecka at gmail dot com Summary: Heap Overflow Vulnerability in imagecrop() Status: Closed -Type: Security +Type: Bug Package: GD related Operating System: all PHP Version: 5.5.7 Assigned To: pajoye Block user comment: N Private report: Y New Comment: Drop the security type as 5.5.9 is now released. Previous Comments: ------------------------------------------------------------------------ [2013-12-28 21:07:41] kuba dot brecka at gmail dot com Please use CVE-2013-7226 for this issue. ------------------------------------------------------------------------ [2013-12-28 13:33:51] remi@php.net @laruence, I think it could make sense to apply your check in the PHP side... ------------------------------------------------------------------------ [2013-12-28 13:31:05] remi@php.net The fix for this bug has been committed. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. For Windows: http://windows.php.net/snapshots/ Thank you for the report, and for helping us make PHP better. See http://git.php.net/?p=php-src.git;a=commitdiff;h=8f4a5373bb71590352fd934028d6dde5bc18530b ------------------------------------------------------------------------ [2013-12-28 09:45:19] pajoye@php.net @remi Please sync with gd 2.1.x tree isntead, there are all bug fixes in it and no new features. ------------------------------------------------------------------------ [2013-12-28 08:20:56] remi@php.net 2 patches proposal (tested on php 5.5) v1: position out of src image will return NULL. v2: position out of the src image, will return a blank image, which is consistent with current size check: As the size check is done "after" image allocation, so, result image could be partially blank, but always of requested size. We could also think of moving size check "before" allocation, but this will be a BC break. New size check seems better (even if the test is not really readable) and should be integer overflow free. For PHP 5.6, I will prefer to see bundled libgd updated to upstream version 2.1.x ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=66356 -- Edit this bug report at https://bugs.php.net/bug.php?id=66356&edit=1

« previous php.bugs (#184273) next »