Bug #72045 [Com]: Stack-overflow on imagefilltoborder
Edit report at https://bugs.php.net/bug.php?id=72045&edit=1
ID: 72045
Comment by: fernando at null-life dot com
Reported by: fernando at null-life dot com
Summary: Stack-overflow on imagefilltoborder
Status: Open
Type: Bug
Package: GD related
Operating System: Linux
PHP Version: 5.6.20
Block user comment: N
Private report: N
New Comment:
I think this can be closed.
This is a duplicate of https://bugs.php.net/bug.php?id=66387 when using
systemwide libgd, and this was recently fixed here for libgd (CVE-2015-8874):
https://github.com/libgd/libgd/issues/213
Previous Comments:
------------------------------------------------------------------------
[2016-04-17 18:14:17] fernando at null-life dot com
Description:
------------
Run test script with PHP 5.6.20.
Test script:
---------------
<?php
$img = imagecreatetruecolor (100 , 100);
imagefilltoborder($img, 100, 1, 257, -10066304);
Expected result:
----------------
No crash
Actual result:
--------------
ERROR: AddressSanitizer: stack-overflow on address 0xbf142ff8 (pc 0xb299e348 bp 0x00000064 sp
0xbf142ffc T0)
#0 0xb299e347 in gdImageFillToBorder (/usr/lib/i386-linux-gnu/libgd.so.3+0xb347)
#1 0xb299e507 in gdImageFillToBorder (/usr/lib/i386-linux-gnu/libgd.so.3+0xb507)
#2 0xb299e4e7 in gdImageFillToBorder (/usr/lib/i386-linux-gnu/libgd.so.3+0xb4e7)
...
#248 0xb299e4e7 in gdImageFillToBorder (/usr/lib/i386-linux-gnu/libgd.so.3+0xb4e7)
#249 0xb299e507 in gdImageFillToBorder (/usr/lib/i386-linux-gnu/libgd.so.3+0xb507)
#250 0xb299e4e7 in gdImageFillToBorder (/usr/lib/i386-linux-gnu/libgd.so.3+0xb4e7)
SUMMARY: AddressSanitizer: stack-overflow ??:0 gdImageFillToBorder
==8427==ABORTING
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72045&edit=1
Thread (2 messages)