Bug #72115 [NEW]: imagexbm read out of bounds
| From: | fernando at null-life dot com | Date: | Thu, 28 Apr 2016 03:17:39 +0000 |
| Subject: | Bug #72115 [NEW]: imagexbm read out of bounds | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-200798@lists.php.net to get a copy of this message | ||
From: fernando at null-life dot com
Operating system: Linux
PHP version: 5.5.34
Package: GD related
Bug Type: Bug
Bug description:imagexbm read out of bounds
Description:
------------
Compile PHP with ASAN. Only affects PHP 5.5.34 since
https://bugs.php.net/bug.php?id=66339 reported
by me too and patched on
5.6 prevents me from triggering it.
BP on https://github.com/php/php-src/blob/PHP-5.5/ext/gd/gd_ctx.c#L39
(gdb) r
The program being debugged has been started already.
Start it from the beginning? (y or n) y
Starting program: /home/user/php/php-55/sapi/cli/php -n
-dextension=/home/user/php/php-55/modules/gd.so /home/user/img.php
[Thread debugging using libthread_db enabled]
Using host libthread_db library
"/lib/i386-linux-gnu/libthread_db.so.1".
Breakpoint 1, _php_image_output_putbuf (ctx=0xb46ddf38, buf=0xbfffa69c,
l=8017) at /home/user/php/php-55/ext/gd/gd_ctx.c:39
39 return php_write((void *)buf, l TSRMLS_CC);
(gdb) print l
$7 = 8017
This length comes from the failed vsnprintf attempt [1] to copy more
than 8000 chars on a 4095 buffer, vsnprintf [2] "a return value of size
or more means that the output was truncated", however libgd returns this
length and PHP prints more information from memory that it should.
While this issue directly comes from the fact that libgd isn't checking
the vsnprintf return value, PHP should probably backport the #66339
patch to 5.5 to prevent it.
[1] https://github.com/libgd/libgd/blob/master/src/gd_xbm.c#L188
[2] http://linux.die.net/man/3/vsnprintf /
Test script:
---------------
<?php
$var1=imagecreatetruecolor ( 2 , 2);
$var2=str_repeat("ABCD", 1030);
$var3=0;
imagexbm($var1, $var2, $var3);
Expected result:
----------------
Error trying to create a long filename or something (current PHP 5.6
behavior)
Image on stdout (PHP 5.5 *broken* behavior)
Actual result:
--------------
....ABCDAB?\??G?y??!??=F?8?m??F?y?????J?P????0
?<??4C?!?8?m??O?P?m????P?????? =F??O?P?m????P???/
N?!?l?m?8?m???m???m????P?m?P???!?8?m?????????A?N??M?0
??????0 ,?m?A`p? 5 ??
??0 ??0 0
?????\?A`p? ?>?? ??l?m?l?m?@?C??l?m?l?m?@M??C??0
????7<??@P?????m???m????@???-90 ?=
??GL?m?O?m? ? ?i?8?m???O?`??????0
???AhW? ?? ?0 ?<??? -90 ?=
??G??m???m????tu_ ?? _?q_ ?@?=
0
@?=
?l??0 ?<?? \?9?M?pl?(?m?@?=
?l?Z? ??m?????0
(?m?ll??l??Ml??l??l?0C?m?8?m?d???l??l?(?m?? 0
?l?@?=
??=
?Th 4?m?8?Ghp?=
?Sh ??=
Sh ?=
,?G?%? ?l?`?=
,?G?%? ?$? 0
@?=
?.G ??m?p???<?????D??? ?=
??=
}?G0???F??0??????A?D? ?,G ?=
??m?+d??&=l?m??4K? ??D?m?-90 ?=
??GK?m?N?m?\?7{6?? ????m????A?0
????\?<?{6?? ??J?m?8?m?????0<??8?m???????0 <??0
\?8?m??,G 0
????}~ ??????G8?m?_!W??r_!W\?{6?? ??~??0<?????????0
~??<??0
?, ??????<??0
@???`
???????????????
?hp-55/sapi/cli/p???A??? ?) ?? `???????=
???@???`??? ????????=
????"????}!W???"#???A??? ?
????????/home/user/img.php?H?c??~???????<???\ W?ptm\ W?J?m\
W?J?????\?H?c?{6?? ?????#0<???$?`???#0
???<??0
?, ?$????P????????`??????#????A??? ?)
/home/user/php/php-55/sapi/cli/php???H?????????H???4 9v????
????????x??? ?L??????? ??h+????? ?L! ??????? ?? E?u?@??????~6?:b?
???=?????? ??????=?? ??t??? E?u?mG?????F??????????????
=================================================================
==3897==ERROR: AddressSanitizer: stack-buffer-underflow on address
0xbfffb750 at pc 0xb7aa6dbd bp 0xbfffa408 sp 0xbfff9fdc
READ of size 8017 at 0xbfffb750 thread T0
#0 0xb7aa6dbc (/usr/lib/i386-linux-gnu/libasan.so.2+0x3ddbc)
#1 0x99388cf in sapi_cli_single_write
/home/user/php/php-55/sapi/cli/php_cli.c:273
#2 0x9938a01 in sapi_cli_ub_write
/home/user/php/php-55/sapi/cli/php_cli.c:308
#3 0x920f82f in php_output_op
/home/user/php/php-55/main/output.c:1094
#4 0x920f82f in php_output_write
/home/user/php/php-55/main/output.c:270
#5 0x919debb in php_write /home/user/php/php-55/main/main.c:671
#6 0xb44b1a3b in _php_image_output_putbuf
/home/user/php/php-55/ext/gd/gd_ctx.c:39
#7 0xb44638ba (/usr/lib/i386-linux-gnu/libgd.so.3+0x318ba)
#8 0xb4463ddf in gdImageXbmCtx
(/usr/lib/i386-linux-gnu/libgd.so.3+0x31ddf)
#9 0xb44e0a2e in _php_image_output_ctx
/home/user/php/php-55/ext/gd/gd_ctx.c:187
#10 0xb44e0a2e in zif_imagexbm
/home/user/php/php-55/ext/gd/gd.c:2702
#11 0x992dc59 in zend_do_fcall_common_helper_SPEC
/home/user/php/php-55/Zend/zend_vm_execute.h:550
#12 0x96854cf in execute_ex
/home/user/php/php-55/Zend/zend_vm_execute.h:363
#13 0x99225d6 in zend_execute
/home/user/php/php-55/Zend/zend_vm_execute.h:388
#14 0x9472ed1 in zend_execute_scripts
/home/user/php/php-55/Zend/zend.c:1327
#15 0x91a7e7c in php_execute_script
/home/user/php/php-55/main/main.c:2525
#16 0x99379c4 in do_cli
/home/user/php/php-55/sapi/cli/php_cli.c:994
#17 0x808a06c in main /home/user/php/php-55/sapi/cli/php_cli.c:1378
#18 0xb764c636 in __libc_start_main
(/lib/i386-linux-gnu/libc.so.6+0x18636)
#19 0x808a78a (/home/user/php/php-55/sapi/cli/php+0x808a78a)
Address 0xbfffb750 is located in stack of thread T0 at offset 0 in
frame
#0 0xb44dfe0f in zif_imagexbm
/home/user/php/php-55/ext/gd/gd.c:2701
This frame has 6 object(s):
[32, 36) 'imgind' <== Memory access at offset 0 partially underflows
this variable
[96, 100) 'file' <== Memory access at offset 0 partially underflows
this variable
[160, 164) 'file_len' <== Memory access at offset 0 partially
underflows this variable
[224, 228) 'quality' <== Memory access at offset 0 partially
underflows this variable
[288, 292) 'basefilter' <== Memory access at offset 0 partially
underflows this variable
[352, 356) 'to_zval' <== Memory access at offset 0 partially
underflows this variable
HINT: this may be a false positive if your program uses some custom
stack unwind mechanism or swapcontext
(longjmp and C++ exceptions *are* supported)
SUMMARY: AddressSanitizer: stack-buffer-underflow ??:0 ??
Shadow bytes around the buggy address:
0x37fff690: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x37fff6a0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x37fff6b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x37fff6c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x37fff6d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
=>0x37fff6e0: 00 00 00 00 00 00 00 00 00 00[f1]f1 f1 f1 04 f4
0x37fff6f0: f4 f4 f2 f2 f2 f2 04 f4 f4 f4 f2 f2 f2 f2 04 f4
0x37fff700: f4 f4 f2 f2 f2 f2 04 f4 f4 f4 f2 f2 f2 f2 04 f4
0x37fff710: f4 f4 f2 f2 f2 f2 04 f4 f4 f4 f3 f3 f3 f3 00 00
0x37fff720: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x37fff730: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Heap right redzone: fb
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack partial redzone: f4
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
==3897==ABORTING
--
Edit bug report at https://bugs.php.net/bug.php?id=72115&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72115&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72115&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72115&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=72115&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=72115&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=72115&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=72115&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=72115&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=72115&r=support
Expected behavior: https://bugs.php.net/fix.php?id=72115&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=72115&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=72115&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=72115&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72115&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=72115&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=72115&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=72115&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72115&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=72115&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=72115&r=mysqlcfg