Sec Bug->Bug #72350 [Opn]: gdImageFillToBorder stack-overflow when invalid color is used

From: Date: Sun, 12 Jun 2016 22:56:02 +0000
Subject: Sec Bug->Bug #72350 [Opn]: gdImageFillToBorder stack-overflow when invalid color is used
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201557@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72350&edit=1 ID: 72350 Updated by: stas@php.net Reported by: fernando at null-life dot com Summary: gdImageFillToBorder stack-overflow when invalid color is used Status: Open -Type: Security +Type: Bug Package: GD related Operating System: * PHP Version: 7.0.7 -Assigned To: +Assigned To: pajoye Block user comment: N Private report: Y New Comment: Pierre, I assume you'll merge the patch for PHP embedded libgd? Previous Comments: ------------------------------------------------------------------------ [2016-06-07 12:51:12] pajoye@php.net For one this bug is already public so making it private only for php helps little. :) About the bug itself. It requires buggy code and local access. I am fine to have a CVE with a low level of severety, for clarity. ------------------------------------------------------------------------ [2016-06-07 10:24:01] cmb@php.net Related To: Bug #72045 ------------------------------------------------------------------------ [2016-06-07 05:10:31] fernando at null-life dot com I reported the original github issue. May I understand the judgement to consider it security relevant or not? When you (gd) guys fixed this [1][2](also reported by me to PHP) considered it a security relevant fix and somebody requested a CVE (Debian I believe) [1] https://github.com/libgd/libgd/issues/213 [2] https://bugs.php.net/bug.php?id=66387 Both cause the same and occur because lack of validation of supplied values calling the function. This issue is not security relevant because...? ------------------------------------------------------------------------ [2016-06-07 04:51:34] pajoye@php.net Also not a security issue. See https://github.com/libgd/libgd/issues/215 Sync coming for next php releases. ------------------------------------------------------------------------ [2016-06-07 04:48:05] pajoye@php.net @Stas it is done the same way. Gd is bundled with some php specific behaviors so it is all good. Most contributOrson in Gd are in the core as well. Only thing we do is to be sure to release sec fixes at the same time. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72350 -- Edit this bug report at https://bugs.php.net/bug.php?id=72350&edit=1

« previous php.bugs (#201557) next »