Bug #68713 [Asn]: infinite loop / infinite free
| From: | bugreports at internot dot info | Date: | Sat, 03 Jan 2015 05:23:14 +0000 |
| Subject: | Bug #68713 [Asn]: infinite loop / infinite free | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189617@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68713&edit=1
ID: 68713
User updated by: bugreports at internot dot info
Reported by: bugreports at internot dot info
Summary: infinite loop / infinite free
Status: Assigned
Type: Bug
Package: GD related
Operating System: Linux Ubuntu 14.04
PHP Version: master-Git-2015-01-02 (Git)
Assigned To: remi
Block user comment: N
Private report: N
New Comment:
Ok cool.
@remi: Do you know of any programs using libgd, where gdMalloc does not call an
emalloc-"like" allocator, that just quits on failure?
Thanks,
Previous Comments:
------------------------------------------------------------------------
[2015-01-03 05:15:34] stas@php.net
We may want to merge the upstream for cleanness but doesn't look like security issue in PHP.
------------------------------------------------------------------------
[2015-01-03 05:11:56] stas@php.net
Why the condition is "yy >= yy - 1"? I imagine for unsigned it's the same as yy !=
0 but why not write it this way then?
In any case, emalloc in PHP never returns NULL so in PHP context it is kind of an academic exercise.
------------------------------------------------------------------------
[2015-01-02 08:38:50] bugreports at internot dot info
So you're saying that clean_on_error can never be called, so it can't get to that code?
Why is it there then?
Anyways, if clean_on_error was reached and it did get to that code, it will cause either a denial of
service, or a crash(or both). the crash may be exploitable due to it calling invalid memory. Perhaps
somebody that knows more about the security of PHP(aka. not me) should comment.
Thanks,
------------------------------------------------------------------------
[2015-01-02 08:29:46] remi@php.net
In PHP gdMalloc is mapped to emalloc which will never return NULL (but bailout with memory limit
error), so the "clean_on_error" will never be used.
And I haven't say there is no bug, yes the infinite loop exists in libgd (not in PHP), I just
say I can't see how this can raise security issue.
------------------------------------------------------------------------
[2015-01-02 08:21:09] bugreports at internot dot info
Hi,
Why do you think this is not a sec. issue?
I think(but am not 100% sure) that it will cause the loop to go down the 0, then it'll go to
-1(aka. max int), and will try to free invalid places.
e.g:
unsigned int y = 5;
unsigned int yy;
for (yy = y; yy >= yy - 1; y--) {
printf("%u\n", y);
}
outputs:
$ ./a.out | head -n10
5
4
3
2
1
0
4294967295
4294967294
4294967293
1. it will go on forever, and 2. it will try to free invalid memory.
Thanks,
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68713
--
Edit this bug report at https://bugs.php.net/bug.php?id=68713&edit=1