Bug #72350 [Asn]: gdImageFillToBorder stack-overflow when invalid color is used
| From: | pajoye@php.net | Date: | Mon, 13 Jun 2016 02:17:06 +0000 |
| Subject: | Bug #72350 [Asn]: gdImageFillToBorder stack-overflow when invalid color is used | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-201559@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72350&edit=1
ID: 72350
Updated by: pajoye@php.net
Reported by: fernando at null-life dot com
Summary: gdImageFillToBorder stack-overflow when invalid
color is used
Status: Assigned
Type: Bug
Package: GD related
Operating System: *
PHP Version: 7.0.7
-Assigned To: pajoye
+Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Yes and it is done already.
I am not sure if I have access to 5.5 but 5.6+ has it already.
It was committed when we had issues with our boxes so mails did not make it along other hooks.
The commit: https://github.com/php/php-src/commit/6d3fa654b702c8762aa80ab795080f5c4464d677
It was public already that's why I committed directly. I also ask Anatol to merge it to 5.5 so
it will get into the last release for this branch.
Previous Comments:
------------------------------------------------------------------------
[2016-06-12 22:56:00] stas@php.net
Pierre, I assume you'll merge the patch for PHP embedded libgd?
------------------------------------------------------------------------
[2016-06-07 12:51:12] pajoye@php.net
For one this bug is already public so making it private only for php helps little. :)
About the bug itself. It requires buggy code and local access. I am fine to have a CVE with a low
level of severety, for clarity.
------------------------------------------------------------------------
[2016-06-07 10:24:01] cmb@php.net
Related To: Bug #72045
------------------------------------------------------------------------
[2016-06-07 05:10:31] fernando at null-life dot com
I reported the original github issue. May I understand the judgement to consider it security
relevant or not?
When you (gd) guys fixed this [1][2](also reported by me to PHP) considered it a security relevant
fix and somebody requested a CVE (Debian I believe)
[1] https://github.com/libgd/libgd/issues/213
[2] https://bugs.php.net/bug.php?id=66387
Both cause the same and occur because lack of validation of supplied values calling the function.
This issue is not security relevant because...?
------------------------------------------------------------------------
[2016-06-07 04:51:34] pajoye@php.net
Also not a security issue.
See https://github.com/libgd/libgd/issues/215
Sync coming for next php releases.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72350
--
Edit this bug report at https://bugs.php.net/bug.php?id=72350&edit=1