Bug #71534 [Fbk->Opn]: Type confusion in exif_read_data() leading to heap overflow in debug mode
| From: | hlt99 at blinkenshell dot org | Date: | Fri, 05 Aug 2016 07:23:34 +0000 |
| Subject: | Bug #71534 [Fbk->Opn]: Type confusion in exif_read_data() leading to heap overflow in debug mode | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202943@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71534&edit=1
ID: 71534
User updated by: hlt99 at blinkenshell dot org
Reported by: hlt99 at blinkenshell dot org
Summary: Type confusion in exif_read_data() leading to heap
overflow in debug mode
-Status: Feedback
+Status: Open
Type: Bug
Package: EXIF related
Operating System: Arch Linux (64-bit)
PHP Version: 7.0.3
Block user comment: N
Private report: N
New Comment:
Please take this patch with a grain of salt as it may have unintended side effects! I merely used it
to prevent afl-fuzz from running into the crash over and over again.
Now, after you've been warned: patch reuploaded.
Previous Comments:
------------------------------------------------------------------------
[2016-08-05 06:15:09] kalle@php.net
Hi
Could you re-upload the patch somewhere so I can take a look at it while fixing some other exif
related things?
Thanks!
------------------------------------------------------------------------
[2016-02-17 17:35:19] hlt99 at blinkenshell dot org
Be aware that this bug appears harmless just because PHP memory checks prevent it from surfacing. If
there ever is a way around these checks (by introducing another bug in the future or whatever) this
becomes a real problem.
(I referenced this other bug to show just that. Even if it works in debug-mode PHP only this time.)
------------------------------------------------------------------------
[2016-02-15 08:23:47] stas@php.net
Debug mode should never be used in production, thus reclassifying as non-security.
------------------------------------------------------------------------
[2016-02-08 17:44:47] hlt99 at blinkenshell dot org
I made a mistake in the initial report: This particular bug is also present in PHP-5.6.18 although
it doesn't surface as a segfault because PHP-5.6.18 is not affected by #71535.
One way to patch this bug would be to rewrite the format tag before setting
ImageInfo->Thumbnail.size via exif_convert_any_to_int(). [2]
[2] http://hlt99.blinkenshell.org/php/exif-type-conf.patch
------------------------------------------------------------------------
[2016-02-05 11:16:57] hlt99 at blinkenshell dot org
Seems like I can't update the original bug description, so here is the reference to the other
bug:
[1] For more info on the zend_mm_alloc_heap() bug refer to #71535!
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71534
--
Edit this bug report at https://bugs.php.net/bug.php?id=71534&edit=1