Bug #66387 [Opn->Ana]: Stack overflow with imagefilltoborder
Edit report at https://bugs.php.net/bug.php?id=66387&edit=1
ID: 66387
Updated by: cmb@php.net
Reported by: fernando at null-life dot com
Summary: Stack overflow with imagefilltoborder
-Status: Open
+Status: Analyzed
Type: Bug
Package: GD related
-Operating System: Windows
+Operating System: *
-PHP Version: 5.5.7
+PHP Version: 5.6.11
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Well, the recursive algorithm might not be the perfect solution,
but the real issue here is that a very large negative coordinate
is passed to imagefilltoborder(). If the coordinates were properly
clipped[1], the test script would run fine.
Of course, the same problem would occur for very large images, but
its not unlikely that such images can't be allocated anyway (see
bug #66488), and I expect other issues with very large images as
well.
[1] <https://github.com/php/php-src/blob/PHP-5.5.7/ext/gd/libgd/gd.c#L1775-L1780>
Previous Comments:
------------------------------------------------------------------------
[2014-01-06 17:50:23] scott at arciszewski dot me
https://github.com/php/php-src/blob/PHP-5.5.7/ext/gd/libgd/gd.c#L1827
Indeed. Does anyone want to patch it for 5.5.8?
------------------------------------------------------------------------
[2014-01-02 06:03:50] fernando at null-life dot com
Description:
------------
There is a stack overflow inside imagefilltoborder.
Test script:
---------------
$im = imagecreatetruecolor(20, 20);
$c = imagecolorallocate($im, 255, 0, 0);
imagefilltoborder($im, 0, -999355, $c, $c);
Expected result:
----------------
Not crash/image
Actual result:
--------------
(13cc.e2c): Stack overflow - code c00000fd (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=00000000 ebx=fff4cb4b ecx=000f4240 edx=00000000 esi=00d9dca0 edi=ffffffff
eip=675cca19 esp=003d3000 ebp=003d3004 iopl=0 nv up ei ng nz ac pe cy
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00210297
*** WARNING: Unable to verify checksum for C:\php\php_gd2.dll
php_gd2!php_gd_gdImageSetPixel+0x9:
675cca19 57 push edi
0:000> k
ChildEBP RetAddr
003d3004 675cb829 php_gd2!php_gd_gdImageSetPixel+0x9
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\libgd\gd.c @ 723]
003d3034 675cb938 php_gd2!php_gd_gdImageFillToBorder+0x79
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\libgd\gd.c @ 1786]
003d3068 675cb938 php_gd2!php_gd_gdImageFillToBorder+0x188
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\libgd\gd.c @ 1827]
003d309c 675cb938 php_gd2!php_gd_gdImageFillToBorder+0x188
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\libgd\gd.c @ 1827]
003d30d0 675cb938 php_gd2!php_gd_gdImageFillToBorder+0x188
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\libgd\gd.c @ 1827]
003d3104 675cb938 php_gd2!php_gd_gdImageFillToBorder+0x188
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\libgd\gd.c @ 1827]
003d3138 675cb938 php_gd2!php_gd_gdImageFillToBorder+0x188
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\libgd\gd.c @ 1827]
003d316c 675cb938 php_gd2!php_gd_gdImageFillToBorder+0x188
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\libgd\gd.c @ 1827]
003d31a0 675cb938 php_gd2!php_gd_gdImageFillToBorder+0x188
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\libgd\gd.c @ 1827]
...
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66387&edit=1
Thread (6 messages)