Bug #71534 [Opn->Asn]: Type confusion in exif_read_data() leading to heap overflow in debug mode

From: Date: Fri, 05 Aug 2016 08:17:08 +0000
Subject: Bug #71534 [Opn->Asn]: Type confusion in exif_read_data() leading to heap overflow in debug mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202947@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71534&edit=1 ID: 71534 Updated by: kalle@php.net Reported by: hlt99 at blinkenshell dot org Summary: Type confusion in exif_read_data() leading to heap overflow in debug mode -Status: Open +Status: Assigned Type: Bug Package: EXIF related Operating System: Arch Linux (64-bit) PHP Version: 7.0.3 -Assigned To: +Assigned To: kalle Block user comment: N Private report: N New Comment: Hi Thanks a lot for the patch! I can kinda follow were you are going with this and I think I can work with that. As you note in the patch, returning TAG_FMT_UNDEFINED can have a side effect, since it is used at the end of the big if/else as we pass it to exif_iif_add_tag(). Another thing I was wondering about, is that in your patch, you only cast it to an unsigned int before two instances of exif_convert_any_to_int() (in case the ImageInfo->Thumbnail.data hits either TAG_JPEG_INTERCHANGE_FORMAT_LEN or TAG_STRIP_BYTE_COUNTS), but we still have a few others, is there any reasoning behind this or just an oversight? Oh and one last favor, the PoC.tiff, could you also re-upload that so I can toy around with it? Previous Comments: ------------------------------------------------------------------------ [2016-08-05 07:23:32] hlt99 at blinkenshell dot org Please take this patch with a grain of salt as it may have unintended side effects! I merely used it to prevent afl-fuzz from running into the crash over and over again. Now, after you've been warned: patch reuploaded. ------------------------------------------------------------------------ [2016-08-05 06:15:09] kalle@php.net Hi Could you re-upload the patch somewhere so I can take a look at it while fixing some other exif related things? Thanks! ------------------------------------------------------------------------ [2016-02-17 17:35:19] hlt99 at blinkenshell dot org Be aware that this bug appears harmless just because PHP memory checks prevent it from surfacing. If there ever is a way around these checks (by introducing another bug in the future or whatever) this becomes a real problem. (I referenced this other bug to show just that. Even if it works in debug-mode PHP only this time.) ------------------------------------------------------------------------ [2016-02-15 08:23:47] stas@php.net Debug mode should never be used in production, thus reclassifying as non-security. ------------------------------------------------------------------------ [2016-02-08 17:44:47] hlt99 at blinkenshell dot org I made a mistake in the initial report: This particular bug is also present in PHP-5.6.18 although it doesn't surface as a segfault because PHP-5.6.18 is not affected by #71535. One way to patch this bug would be to rewrite the format tag before setting ImageInfo->Thumbnail.size via exif_convert_any_to_int(). [2] [2] http://hlt99.blinkenshell.org/php/exif-type-conf.patch ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71534 -- Edit this bug report at https://bugs.php.net/bug.php?id=71534&edit=1

« previous php.bugs (#202947) next »