Bug #70052 [Opn]: getimagesize() + WBMP integer overflow

From: Date: Mon, 13 Jul 2015 08:45:48 +0000
Subject: Bug #70052 [Opn]: getimagesize() + WBMP integer overflow
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194380@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70052&edit=1 ID: 70052 Updated by: cmb@php.net Reported by: p at wspnr dot com Summary: getimagesize() + WBMP integer overflow Status: Open Type: Bug Package: GetImageSize related Operating System: Debian Linux PHP Version: master-Git-2015-07-12 (Git) Block user comment: N Private report: N New Comment: To my knowledge, MP4 files start with a 32bit number (big endian) that tells the size of the first atom. It *might* be possible that there are MP4 files which are mistaken for WBMP even though the dimensions are restricted for "valid" WBMP files. And of course it's always possible that there are some arbitrary binary files which can be mistaken for WBMP. It might be best to add a notice to the getimagesize() man page, that this function should not be used to try to detect whether a given file is an image file. finfo seems to be preferable for that purpose, but even that is not bullet proof. > Also, WBMPs smaller than 12 bytes produce a "Read error!". Indeed! That's caused by <https://github.com/php/php-src/blob/php-5.6.11/ext/standard/image.c#L1276-L1279>. Previous Comments: ------------------------------------------------------------------------ [2015-07-12 23:00:52] p at wspnr dot com Best reason I can come up with is that the MPEG video file signature starts with "00 00 01 BA" which is the start of a valid WBMP header as well. That would result in a WBMP with a height of 7424 or greater. Also, WBMPs smaller than 12 bytes produce a "Read error!". ------------------------------------------------------------------------ [2015-07-12 17:16:45] cmb@php.net The size limitation of 2048x2048 has been introduced as fix[1] for bug #29443. I'm not sure about the exact reasoning, but apparently very large WBMPs can be considered rather uncommon, and obviously the size restriction fixed the bug. [1] <https://github.com/php/php-src/commit/972940509f2c43adeb1723fd17584d3e992997ae> ------------------------------------------------------------------------ [2015-07-12 14:25:41] p at wspnr dot com Description: ------------ 1. getimagesize() seems to artificially limit the size of valid WBMPs to 2048x2048, even though imagecreatefromwbmp() will happily load WBMPs of arbitrary dimensions. 2. There is an integer overflow bug that occurs when the size of the supplied WBMP, as indicated in the header, is greater than (2^31-1) resulting in invalid WBMPs returning a "valid" response. This may cause problems for scripts that use getimagesize() to detect whether a file is an image or not. Test script: --------------- -- WBMP 1, 2047x2047 -- 00 00 80 80 80 8F 7F 80 80 80 8F 7F -- WBMP 2, 2048x2048 -- 00 00 80 80 80 90 00 80 80 80 90 00 -- WBMP 3, 2049x2049 -- 00 00 80 80 80 90 01 80 80 80 90 01 -- WBMP 4, (2^31)x(2^31) -- 00 00 88 80 80 80 00 88 80 80 80 00 -- WBMP 5, (2^32-1)x(2^32-1) -- 00 00 8F FF FF FF 7F 8F FF FF FF 7F -- PHP -- <?php for($i = 1; $i <= 5); ++$i) { echo "WBMP ", $i, PHP_EOL; var_dump(getimagesize("wbmp" . $i . ".wbmp")); } Expected result: ---------------- WBMP 1 array(5) { [0]=> int(2047) [1]=> int(2047) [2]=> int(15) [3]=> string(26) "width="2047" height="2047"" ["mime"]=> string(18) "image/vnd.wap.wbmp" } WBMP 2 array(5) { [0]=> int(2048) [1]=> int(2048) [2]=> int(15) [3]=> string(26) "width="2048" height="2048"" ["mime"]=> string(18) "image/vnd.wap.wbmp" } WBMP 3 bool(false) WBMP 4 bool(false) WBMP 5 bool(false) Actual result: -------------- WBMP 1 array(5) { [0]=> int(2047) [1]=> int(2047) [2]=> int(15) [3]=> string(26) "width="2047" height="2047"" ["mime"]=> string(18) "image/vnd.wap.wbmp" } WBMP 2 array(5) { [0]=> int(2048) [1]=> int(2048) [2]=> int(15) [3]=> string(26) "width="2048" height="2048"" ["mime"]=> string(18) "image/vnd.wap.wbmp" } WBMP 3 bool(false) WBMP 4 array(5) { [0]=> int(2147483648) [1]=> int(2147483648) [2]=> int(15) [3]=> string(40) "width="-2147483648" height="-2147483648"" ["mime"]=> string(18) "image/vnd.wap.wbmp" } WBMP 5 array(5) { [0]=> int(4294967295) [1]=> int(4294967295) [2]=> int(15) [3]=> string(22) "width="-1" height="-1"" ["mime"]=> string(18) "image/vnd.wap.wbmp" } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70052&edit=1

« previous php.bugs (#194380) next »