Sec Bug->Bug #68713 [Asn->Opn]: infinite loop / infinite free

From: Date: Sat, 03 Jan 2015 05:15:34 +0000
Subject: Sec Bug->Bug #68713 [Asn->Opn]: infinite loop / infinite free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189616@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68713&edit=1 ID: 68713 Updated by: stas@php.net Reported by: bugreports at internot dot info Summary: infinite loop / infinite free -Status: Assigned +Status: Open -Type: Security +Type: Bug Package: GD related Operating System: Linux Ubuntu 14.04 PHP Version: master-Git-2015-01-02 (Git) Assigned To: remi Block user comment: N Private report: Y New Comment: We may want to merge the upstream for cleanness but doesn't look like security issue in PHP. Previous Comments: ------------------------------------------------------------------------ [2015-01-03 05:11:56] stas@php.net Why the condition is "yy >= yy - 1"? I imagine for unsigned it's the same as yy != 0 but why not write it this way then? In any case, emalloc in PHP never returns NULL so in PHP context it is kind of an academic exercise. ------------------------------------------------------------------------ [2015-01-02 08:38:50] bugreports at internot dot info So you're saying that clean_on_error can never be called, so it can't get to that code? Why is it there then? Anyways, if clean_on_error was reached and it did get to that code, it will cause either a denial of service, or a crash(or both). the crash may be exploitable due to it calling invalid memory. Perhaps somebody that knows more about the security of PHP(aka. not me) should comment. Thanks, ------------------------------------------------------------------------ [2015-01-02 08:29:46] remi@php.net In PHP gdMalloc is mapped to emalloc which will never return NULL (but bailout with memory limit error), so the "clean_on_error" will never be used. And I haven't say there is no bug, yes the infinite loop exists in libgd (not in PHP), I just say I can't see how this can raise security issue. ------------------------------------------------------------------------ [2015-01-02 08:21:09] bugreports at internot dot info Hi, Why do you think this is not a sec. issue? I think(but am not 100% sure) that it will cause the loop to go down the 0, then it'll go to -1(aka. max int), and will try to free invalid places. e.g: unsigned int y = 5; unsigned int yy; for (yy = y; yy >= yy - 1; y--) { printf("%u\n", y); } outputs: $ ./a.out | head -n10 5 4 3 2 1 0 4294967295 4294967294 4294967293 1. it will go on forever, and 2. it will try to free invalid memory. Thanks, ------------------------------------------------------------------------ [2015-01-02 08:19:38] remi@php.net Also https://bitbucket.org/libgd/gd-libgd/commits/4af76c97a478d4e7c4b64e08ac67abbca7cbd0fb ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68713 -- Edit this bug report at https://bugs.php.net/bug.php?id=68713&edit=1

« previous php.bugs (#189616) next »