Bug #71534 [Fbk->Asn]: Type confusion in exif_read_data() leading to heap overflow in debug mode

From: Date: Sat, 06 Aug 2016 07:40:55 +0000
Subject: Bug #71534 [Fbk->Asn]: Type confusion in exif_read_data() leading to heap overflow in debug mode
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202993@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71534&edit=1 ID: 71534 User updated by: hlt99 at blinkenshell dot org Reported by: hlt99 at blinkenshell dot org Summary: Type confusion in exif_read_data() leading to heap overflow in debug mode -Status: Feedback +Status: Assigned Type: Bug Package: EXIF related Operating System: Arch Linux (64-bit) PHP Version: 7.0.3 Assigned To: kalle Block user comment: N Private report: N New Comment: Sample poc.tiff reuploaded. From my memories: These were the two code paths I found that crashed PHP. To maintain the smallest possible footprint of my naive patch attempt I added the casts to unsigned types only there. However I'm quite sure I did not check the others. So consider it as an oversight. Previous Comments: ------------------------------------------------------------------------ [2016-08-05 08:17:07] kalle@php.net Hi Thanks a lot for the patch! I can kinda follow were you are going with this and I think I can work with that. As you note in the patch, returning TAG_FMT_UNDEFINED can have a side effect, since it is used at the end of the big if/else as we pass it to exif_iif_add_tag(). Another thing I was wondering about, is that in your patch, you only cast it to an unsigned int before two instances of exif_convert_any_to_int() (in case the ImageInfo->Thumbnail.data hits either TAG_JPEG_INTERCHANGE_FORMAT_LEN or TAG_STRIP_BYTE_COUNTS), but we still have a few others, is there any reasoning behind this or just an oversight? Oh and one last favor, the PoC.tiff, could you also re-upload that so I can toy around with it? ------------------------------------------------------------------------ [2016-08-05 07:23:32] hlt99 at blinkenshell dot org Please take this patch with a grain of salt as it may have unintended side effects! I merely used it to prevent afl-fuzz from running into the crash over and over again. Now, after you've been warned: patch reuploaded. ------------------------------------------------------------------------ [2016-08-05 06:15:09] kalle@php.net Hi Could you re-upload the patch somewhere so I can take a look at it while fixing some other exif related things? Thanks! ------------------------------------------------------------------------ [2016-02-17 17:35:19] hlt99 at blinkenshell dot org Be aware that this bug appears harmless just because PHP memory checks prevent it from surfacing. If there ever is a way around these checks (by introducing another bug in the future or whatever) this becomes a real problem. (I referenced this other bug to show just that. Even if it works in debug-mode PHP only this time.) ------------------------------------------------------------------------ [2016-02-15 08:23:47] stas@php.net Debug mode should never be used in production, thus reclassifying as non-security. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71534 -- Edit this bug report at https://bugs.php.net/bug.php?id=71534&edit=1

« previous php.bugs (#202993) next »