Bug #68547 [NEW]: PHP 5.6.2 Exif Header component value check error
| From: | sjh21a at gmail dot com | Date: | Thu, 04 Dec 2014 23:34:42 +0000 |
| Subject: | Bug #68547 [NEW]: PHP 5.6.2 Exif Header component value check error | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-188916@lists.php.net to get a copy of this message | ||
From: sjh21a at gmail dot com
Operating system: Ubuntu 14.04
PHP version: 5.6.3
Package: EXIF related
Bug Type: Bug
Bug description:PHP 5.6.2 Exif Header component value check error
Description:
------------
PHP 5.6.2 Exif Header component value check error
this bug is exif_process_IFD_TAG() function of ext/exif.c
in exif header, get a components value as follows
2818: components = php_ifd_get32u(dir_entry+4,
ImageInfo->motorola_intel);
dir_entry+4 exists in jpg or tiff files, attacker can modify this all.
look at the below code, a wrong check to components value.
2827: if (components < 0) {
2828: exif_error_docref("exif_read_data#error_ifd" EXIFERR_CC,
ImageInfo, E_WARNING, "Process tag(x%04X=%s): Illegal components(%ld)",
tag, exif_get_tagname(tag, tagname, -12, tag_table TSRMLS_CC),
components);
2829: return FALSE;
2830: }
only check to components value is negative, doesn't check to 0 value
if components value was 0, problem occurs in the below code.
2832: byte_count_signed = (int64_t)components *
php_tiff_bytes_per_format[format];
above calculation result are being 0, this can bypass to below code.
2833: if (byte_count_signed < 0 || (byte_count_signed > INT32_MAX)) {
2834: exif_error_docref("exif_read_data#error_ifd" EXIFERR_CC,
ImageInfo, E_WARNING, "Process tag(x%04X=%s): Illegal byte_count", tag,
exif_get_tagname(tag, tagname, -12, tag_table TSRMLS_CC));
2835: return FALSE;
2836: }
effect: an attacker may be free to any memory area, if do not use to
zend_mm, use after free has occurred.
set the memory to be free from jpg file.
enable zend_mm
root@ubuntu:~/x# php x.php crash.jpg ; gdb -q php core
Segmentation fault (core dumped)
Reading symbols from php...done.
[New LWP 9998]
[Thread debugging using libthread_db enabled]
Using host libthread_db library
"/lib/i386-linux-gnu/libthread_db.so.1".
Core was generated by `php x.php crash.jpg'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 _zend_mm_free_int (heap=0x887ea38, p=0x41414141) at
/root/php-5.6.2/Zend/zend_alloc.c:2076
^^^^^^^^^^^^^
2076 size = ZEND_MM_BLOCK_SIZE(mm_block);
(gdb)
disable zend_mm : # export USE_ZEND_ALLOC=0
root@ubuntu:~/x# php x.php crash.jpg ; gdb -q php core
Segmentation fault (core dumped)
Reading symbols from php...done.
[New LWP 10016]
[Thread debugging using libthread_db enabled]
Using host libthread_db library
"/lib/i386-linux-gnu/libthread_db.so.1".
Core was generated by `php x.php crash.jpg'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 __GI___libc_free (mem=0x41414141) at malloc.c:2929
^^^^^^^^^^^^^^
2929 malloc.c: No such file or directory.
(gdb)
Test script:
---------------
root@ubuntu:~/x# cat x.php
<?
error_reporting(0);
exif_read_data($argv[1]);
exif_thumbnail($argv[1]);
?>
and below link is crash image file
https://www.dropbox.com/s/hius8be0r9h8hk0/trig.jpg?dl=0
--
Edit bug report at https://bugs.php.net/bug.php?id=68547&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=68547&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=68547&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=68547&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=68547&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=68547&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=68547&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=68547&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=68547&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=68547&r=support
Expected behavior: https://bugs.php.net/fix.php?id=68547&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=68547&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=68547&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=68547&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=68547&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=68547&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=68547&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=68547&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=68547&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=68547&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=68547&r=mysqlcfg