Sec Bug->Bug #72350 [Opn]: gdImageFillToBorder stack-overflow when invalid color is used
| From: | stas@php.net | Date: | Sun, 12 Jun 2016 22:56:02 +0000 |
| Subject: | Sec Bug->Bug #72350 [Opn]: gdImageFillToBorder stack-overflow when invalid color is used | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201557@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72350&edit=1
ID: 72350
Updated by: stas@php.net
Reported by: fernando at null-life dot com
Summary: gdImageFillToBorder stack-overflow when invalid
color is used
Status: Open
-Type: Security
+Type: Bug
Package: GD related
Operating System: *
PHP Version: 7.0.7
-Assigned To:
+Assigned To: pajoye
Block user comment: N
Private report: Y
New Comment:
Pierre, I assume you'll merge the patch for PHP embedded libgd?
Previous Comments:
------------------------------------------------------------------------
[2016-06-07 12:51:12] pajoye@php.net
For one this bug is already public so making it private only for php helps little. :)
About the bug itself. It requires buggy code and local access. I am fine to have a CVE with a low
level of severety, for clarity.
------------------------------------------------------------------------
[2016-06-07 10:24:01] cmb@php.net
Related To: Bug #72045
------------------------------------------------------------------------
[2016-06-07 05:10:31] fernando at null-life dot com
I reported the original github issue. May I understand the judgement to consider it security
relevant or not?
When you (gd) guys fixed this [1][2](also reported by me to PHP) considered it a security relevant
fix and somebody requested a CVE (Debian I believe)
[1] https://github.com/libgd/libgd/issues/213
[2] https://bugs.php.net/bug.php?id=66387
Both cause the same and occur because lack of validation of supplied values calling the function.
This issue is not security relevant because...?
------------------------------------------------------------------------
[2016-06-07 04:51:34] pajoye@php.net
Also not a security issue.
See https://github.com/libgd/libgd/issues/215
Sync coming for next php releases.
------------------------------------------------------------------------
[2016-06-07 04:48:05] pajoye@php.net
@Stas it is done the same way. Gd is bundled with some php specific behaviors so it is all good.
Most contributOrson in Gd are in the core as well.
Only thing we do is to be sure to release sec fixes at the same time.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72350
--
Edit this bug report at https://bugs.php.net/bug.php?id=72350&edit=1