Bug #70052 [Opn]: getimagesize() + WBMP integer overflow

From: Date: Sun, 12 Jul 2015 17:16:46 +0000
Subject: Bug #70052 [Opn]: getimagesize() + WBMP integer overflow
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194356@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70052&edit=1

 ID:                 70052
 Updated by:         cmb@php.net
 Reported by:        p at wspnr dot com
 Summary:            getimagesize() + WBMP integer overflow
 Status:             Open
 Type:               Bug
 Package:            GetImageSize related
 Operating System:   Debian Linux
 PHP Version:        master-Git-2015-07-12 (Git)
 Block user comment: N
 Private report:     N

 New Comment:

The size limitation of 2048x2048 has been introduced as fix[1] for
bug #29443. I'm not sure about the exact reasoning, but apparently
very large WBMPs can be considered rather uncommon, and obviously
the size restriction fixed the bug. 

[1] <https://github.com/php/php-src/commit/972940509f2c43adeb1723fd17584d3e992997ae>


Previous Comments:
------------------------------------------------------------------------
[2015-07-12 14:25:41] p at wspnr dot com

Description:
------------
1. getimagesize() seems to artificially limit the size of valid WBMPs to 2048x2048, even though
imagecreatefromwbmp() will happily load WBMPs of arbitrary dimensions.

2. There is an integer overflow bug that occurs when the size of the supplied WBMP, as indicated in
the header, is greater than (2^31-1) resulting in invalid WBMPs returning a "valid"
response. This may cause problems for scripts that use getimagesize() to detect whether a file is an
image or not.


Test script:
---------------
-- WBMP 1, 2047x2047 --
00 00 80 80 80 8F 7F 80 80 80 8F 7F

-- WBMP 2, 2048x2048 --
00 00 80 80 80 90 00 80 80 80 90 00

-- WBMP 3, 2049x2049 --
00 00 80 80 80 90 01 80 80 80 90 01

-- WBMP 4, (2^31)x(2^31) --
00 00 88 80 80 80 00 88 80 80 80 00

-- WBMP 5, (2^32-1)x(2^32-1) --
00 00 8F FF FF FF 7F 8F FF FF FF 7F

-- PHP --
<?php
for($i = 1; $i <= 5); ++$i) {
    echo "WBMP ", $i, PHP_EOL;
    var_dump(getimagesize("wbmp" . $i . ".wbmp"));
}

Expected result:
----------------
WBMP 1
array(5) {
  [0]=>
  int(2047)
  [1]=>
  int(2047)
  [2]=>
  int(15)
  [3]=>
  string(26) "width="2047" height="2047""
  ["mime"]=>
  string(18) "image/vnd.wap.wbmp"
}
WBMP 2
array(5) {
  [0]=>
  int(2048)
  [1]=>
  int(2048)
  [2]=>
  int(15)
  [3]=>
  string(26) "width="2048" height="2048""
  ["mime"]=>
  string(18) "image/vnd.wap.wbmp"
}
WBMP 3
bool(false)
WBMP 4
bool(false)
WBMP 5
bool(false)


Actual result:
--------------
WBMP 1
array(5) {
  [0]=>
  int(2047)
  [1]=>
  int(2047)
  [2]=>
  int(15)
  [3]=>
  string(26) "width="2047" height="2047""
  ["mime"]=>
  string(18) "image/vnd.wap.wbmp"
}
WBMP 2
array(5) {
  [0]=>
  int(2048)
  [1]=>
  int(2048)
  [2]=>
  int(15)
  [3]=>
  string(26) "width="2048" height="2048""
  ["mime"]=>
  string(18) "image/vnd.wap.wbmp"
}
WBMP 3
bool(false)
WBMP 4
array(5) {
  [0]=>
  int(2147483648)
  [1]=>
  int(2147483648)
  [2]=>
  int(15)
  [3]=>
  string(40) "width="-2147483648" height="-2147483648""
  ["mime"]=>
  string(18) "image/vnd.wap.wbmp"
}

WBMP 5
array(5) {
  [0]=>
  int(4294967295)
  [1]=>
  int(4294967295)
  [2]=>
  int(15)
  [3]=>
  string(22) "width="-1" height="-1""
  ["mime"]=>
  string(18) "image/vnd.wap.wbmp"
}


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70052&edit=1


Thread (11 messages)

« previous php.bugs (#194356) next »