Bug #68547 [Opn]: PHP 5.6.2 Exif Header component value check error
| From: | sjh21a at gmail dot com | Date: | Thu, 04 Dec 2014 23:36:32 +0000 |
| Subject: | Bug #68547 [Opn]: PHP 5.6.2 Exif Header component value check error | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-188917@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68547&edit=1
ID: 68547
User updated by: sjh21a at gmail dot com
Reported by: sjh21a at gmail dot com
Summary: PHP 5.6.2 Exif Header component value check error
Status: Open
Type: Bug
Package: EXIF related
Operating System: Ubuntu 14.04
PHP Version: 5.6.3
Block user comment: N
Private report: N
New Comment:
i found this bug on php-5.6.2
but still work 5.6.3
Previous Comments:
------------------------------------------------------------------------
[2014-12-04 23:34:41] sjh21a at gmail dot com
Description:
------------
PHP 5.6.2 Exif Header component value check error
this bug is exif_process_IFD_TAG() function of ext/exif.c
in exif header, get a components value as follows
2818: components = php_ifd_get32u(dir_entry+4, ImageInfo->motorola_intel);
dir_entry+4 exists in jpg or tiff files, attacker can modify this all.
look at the below code, a wrong check to components value.
2827: if (components < 0) {
2828: exif_error_docref("exif_read_data#error_ifd" EXIFERR_CC, ImageInfo, E_WARNING,
"Process tag(x%04X=%s): Illegal components(%ld)", tag, exif_get_tagname(tag, tagname, -12,
tag_table TSRMLS_CC), components);
2829: return FALSE;
2830: }
only check to components value is negative, doesn't check to 0 value
if components value was 0, problem occurs in the below code.
2832: byte_count_signed = (int64_t)components * php_tiff_bytes_per_format[format];
above calculation result are being 0, this can bypass to below code.
2833: if (byte_count_signed < 0 || (byte_count_signed > INT32_MAX)) {
2834: exif_error_docref("exif_read_data#error_ifd" EXIFERR_CC, ImageInfo, E_WARNING,
"Process tag(x%04X=%s): Illegal byte_count", tag, exif_get_tagname(tag, tagname, -12,
tag_table TSRMLS_CC));
2835: return FALSE;
2836: }
effect: an attacker may be free to any memory area, if do not use to zend_mm, use after free has
occurred.
set the memory to be free from jpg file.
enable zend_mm
root@ubuntu:~/x# php x.php crash.jpg ; gdb -q php core
Segmentation fault (core dumped)
Reading symbols from php...done.
[New LWP 9998]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/i386-linux-gnu/libthread_db.so.1".
Core was generated by `php x.php crash.jpg'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 _zend_mm_free_int (heap=0x887ea38, p=0x41414141) at /root/php-5.6.2/Zend/zend_alloc.c:2076
^^^^^^^^^^^^^
2076 size = ZEND_MM_BLOCK_SIZE(mm_block);
(gdb)
disable zend_mm : # export USE_ZEND_ALLOC=0
root@ubuntu:~/x# php x.php crash.jpg ; gdb -q php core
Segmentation fault (core dumped)
Reading symbols from php...done.
[New LWP 10016]
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/lib/i386-linux-gnu/libthread_db.so.1".
Core was generated by `php x.php crash.jpg'.
Program terminated with signal SIGSEGV, Segmentation fault.
#0 __GI___libc_free (mem=0x41414141) at malloc.c:2929
^^^^^^^^^^^^^^
2929 malloc.c: No such file or directory.
(gdb)
Test script:
---------------
root@ubuntu:~/x# cat x.php
<?
error_reporting(0);
exif_read_data($argv[1]);
exif_thumbnail($argv[1]);
?>
and below link is crash image file
https://www.dropbox.com/s/hius8be0r9h8hk0/trig.jpg?dl=0
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68547&edit=1