Bug #72350 [Asn]: gdImageFillToBorder stack-overflow when invalid color is used

From: Date: Mon, 13 Jun 2016 02:17:06 +0000
Subject: Bug #72350 [Asn]: gdImageFillToBorder stack-overflow when invalid color is used
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201559@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72350&edit=1 ID: 72350 Updated by: pajoye@php.net Reported by: fernando at null-life dot com Summary: gdImageFillToBorder stack-overflow when invalid color is used Status: Assigned Type: Bug Package: GD related Operating System: * PHP Version: 7.0.7 -Assigned To: pajoye +Assigned To: ab Block user comment: N Private report: N New Comment: Yes and it is done already. I am not sure if I have access to 5.5 but 5.6+ has it already. It was committed when we had issues with our boxes so mails did not make it along other hooks. The commit: https://github.com/php/php-src/commit/6d3fa654b702c8762aa80ab795080f5c4464d677 It was public already that's why I committed directly. I also ask Anatol to merge it to 5.5 so it will get into the last release for this branch. Previous Comments: ------------------------------------------------------------------------ [2016-06-12 22:56:00] stas@php.net Pierre, I assume you'll merge the patch for PHP embedded libgd? ------------------------------------------------------------------------ [2016-06-07 12:51:12] pajoye@php.net For one this bug is already public so making it private only for php helps little. :) About the bug itself. It requires buggy code and local access. I am fine to have a CVE with a low level of severety, for clarity. ------------------------------------------------------------------------ [2016-06-07 10:24:01] cmb@php.net Related To: Bug #72045 ------------------------------------------------------------------------ [2016-06-07 05:10:31] fernando at null-life dot com I reported the original github issue. May I understand the judgement to consider it security relevant or not? When you (gd) guys fixed this [1][2](also reported by me to PHP) considered it a security relevant fix and somebody requested a CVE (Debian I believe) [1] https://github.com/libgd/libgd/issues/213 [2] https://bugs.php.net/bug.php?id=66387 Both cause the same and occur because lack of validation of supplied values calling the function. This issue is not security relevant because...? ------------------------------------------------------------------------ [2016-06-07 04:51:34] pajoye@php.net Also not a security issue. See https://github.com/libgd/libgd/issues/215 Sync coming for next php releases. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=72350 -- Edit this bug report at https://bugs.php.net/bug.php?id=72350&edit=1

« previous php.bugs (#201559) next »