Bug #66590 [Csd]: imagewebp() doesn't pad to even length

From: Date: Sun, 19 Jul 2015 15:54:28 +0000
Subject: Bug #66590 [Csd]: imagewebp() doesn't pad to even length
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-194555@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66590&edit=1 ID: 66590 Updated by: cmb@php.net Reported by: hbengali at chromium dot org Summary: imagewebp() doesn't pad to even length Status: Closed Type: Bug Package: GD related Operating System: * PHP Version: 5.6.11 Assigned To: cmb Block user comment: N Private report: N New Comment: Reported upstream against libgd: <https://github.com/libgd/libgd/issues/176>. Previous Comments: ------------------------------------------------------------------------ [2015-07-19 15:48:44] cmb@php.net Automatic comment on behalf of cmb Revision: http://git.php.net/?p=php-src.git;a=commit;h=96e42403d5e5e3e9c39522bda3017b03a8fe2ebc Log: Fix #66590: imagewebp() doesn't pad to even length ------------------------------------------------------------------------ [2015-07-19 15:07:02] cmb@php.net Indeed, I can confirm this issue. Consider the following simple test script: <?php $im = imagecreatetruecolor(75, 75); $red = imagecolorallocate($im, 255, 0, 0); imagefilledrectangle($im, 0, 0, 74, 74, $red); imagewebp($im, __DIR__ . '/bug66590.webp'); ?> This fails to create a valid Webp image file. display (ImageMagick 6.9.1-2), for instance, reports: "insufficient image data in file [...]". The length in the RIFF chunk is given as 92 bytes, so the file size should be 100 bytes (8 bytes RIFF header size), but it's only 99 bytes. The supplied patch obviously fixes this issue. Thanks! ------------------------------------------------------------------------ [2014-01-28 00:43:18] hbengali at chromium dot org Here is a proposed fix from one of the WebP developers with the disclaimer that it is untested and may have incorrect local style. diff --git a/ext/gd/libgd/webpimg.c b/ext/gd/libgd/webpimg.c index 01bef93..ca4e9bc 100644 --- a/ext/gd/libgd/webpimg.c +++ b/ext/gd/libgd/webpimg.c @@ -778,6 +778,18 @@ WebPResult WebPEncode(const uint8* Y, (chunk_size >> 16) & 255, (chunk_size >> 24) & 255 }; memcpy(*p_out, kRiffHeader, kRiffHeaderSize); + if (img_size_bytes & 1) { /* write a padding byte */ + const int new_size = *p_out_size_bytes + 1; + unsigned char* p = (unsigned char*)realloc(*p_out, new_size); + if (p == NULL) { + free(*p_out); + *p_out = NULL; + *p_out_size_bytes = 0; + return webp_failure; + } + p[new_size - 1] = 0; + *p_out_size_bytes = new_size; + } if (psnr) { *psnr = WebPGetPSNR(Y, U, V, *p_out, *p_out_size_bytes); ------------------------------------------------------------------------ [2014-01-28 00:01:40] hbengali at chromium dot org It was brought to my attention that I did not correctly describe the issue. Here is a more accurate summary of what the problem is: The code in php (libgd) uses libvpx and writes the riff manually actually. The code generates the correct even size, but neglects the padding. It's possible older versions of libwebp would decode this, but libwebp 0.4.0 does not. ------------------------------------------------------------------------ [2014-01-27 21:48:09] hbengali at chromium dot org My bad - I did not mean for this to be a bug against the documentation. Thanks for redirecting it. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=66590 -- Edit this bug report at https://bugs.php.net/bug.php?id=66590&edit=1

« previous php.bugs (#194555) next »