Bug #72926 [Opn]: Uninitialized Thumbail Data Leads To Memory Leakage in exif_process_IFD_in_TIFF

From: Date: Mon, 05 Sep 2016 06:45:04 +0000
Subject: Bug #72926 [Opn]: Uninitialized Thumbail Data Leads To Memory Leakage in exif_process_IFD_in_TIFF
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203798@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72926&edit=1 ID: 72926 User updated by: nguyenvuhoang199321 at gmail dot com Reported by: nguyenvuhoang199321 at gmail dot com Summary: Uninitialized Thumbail Data Leads To Memory Leakage in exif_process_IFD_in_TIFF Status: Open Type: Bug Package: EXIF related Operating System: ALL PHP Version: 5.6.26 Block user comment: N Private report: N New Comment: I think it is still security issue. Because, it will lead to memory leakage. Previous Comments: ------------------------------------------------------------------------ [2016-09-05 04:00:12] stas@php.net Same issue as 72627, now fixed in both places. ------------------------------------------------------------------------ [2016-08-23 03:19:19] nguyenvuhoang199321 at gmail dot com Description: ------------ I found other code chunk that leads to memory leakage. ``` exif_process_IFD_in_TIFF(ImageInfo, entry_offset, sub_section_index); if (section_index!=SECTION_THUMBNAIL && entry_tag==TAG_SUB_IFD) { if (ImageInfo->Thumbnail.filetype != IMAGE_FILETYPE_UNKNOWN && ImageInfo->Thumbnail.size && ImageInfo->Thumbnail.offset && ImageInfo->read_thumbnail ) { #ifdef EXIF_DEBUG exif_error_docref(NULL EXIFERR_CC, ImageInfo, E_NOTICE, "%s THUMBNAIL @0x%04X + 0x%04X", ImageInfo->Thumbnail.data ? "Ignore" : "Read", ImageInfo->Thumbnail.offset, ImageInfo->Thumbnail.size); #endif if (!ImageInfo->Thumbnail.data) { ImageInfo->Thumbnail.data = safe_emalloc(ImageInfo->Thumbnail.size, 1, 0); php_stream_seek(ImageInfo->infile, ImageInfo->Thumbnail.offset, SEEK_SET); fgot = php_stream_read(ImageInfo->infile, ImageInfo->Thumbnail.data, ImageInfo->Thumbnail.size); if (fgot < ImageInfo->Thumbnail.size) { EXIF_ERRLOG_THUMBEOF(ImageInfo) } exif_thumbnail_build(ImageInfo); } } } ``` As you can see this code is processing SUB_IFD_TAG and not verify offset of Thumbnail data. Because lack of checking ImageInfo->Thumbnail.offset if an attack set ImageInfo->Thumbnail.offset larger than ImageInfo->FileSize then *php_stream_read* return 0 to fgot, because EXIF_ERRLOG_THUMBEOF was defined as : ``` #define EXIF_ERRLOG_THUMBEOF(ImageInfo) exif_error_docref(NULL EXIFERR_CC, ImageInfo, E_WARNING, "%s", EXIF_ERROR_THUMBEOF); ``` As you can see there is no exit after this error is output. This bug does same problem with this bug i reported before https://bugs.php.net/bug.php?id=72627 Here tiff file : https://drive.google.com/file/d/0B0D1DYQpkA9USUt4c2ZBT21SWE0/view?usp=sharing Test script: --------------- <?php $exif = exif_read_data('exif/gen.tiff',0,0,true); var_dump($exif); $thumb = $exif['THUMBNAIL']['THUMBNAIL']; echo bin2hex($thumb); ?> Actual result: -------------- PHP Warning: exif_read_data(gen.tiff): Error in TIFF: filesize(x00D6) less than size of IFD dir(x0FA0) in /vagrant_extend/audit/exif.php on line 15 Warning: exif_read_data(gen.tiff): Error in TIFF: filesize(x00D6) less than size of IFD dir(x0FA0) in /vagrant_extend/audit/exif.php on line 15 PHP Warning: exif_read_data(gen.tiff): Thumbnail goes IFD boundary or end of file reached in /vagrant_extend/audit/exif.php on line 15 Warning: exif_read_data(gen.tiff): Thumbnail goes IFD boundary or end of file reached in /vagrant_extend/audit/exif.php on line 15 PHP Warning: exif_read_data(gen.tiff): Error in TIFF: filesize(x00D6) less than start of IFD dir(x829A0004) in /vagrant_extend/audit/exif.php on line 15 Warning: exif_read_data(gen.tiff): Error in TIFF: filesize(x00D6) less than start of IFD dir(x829A0004) in /vagrant_extend/audit/exif.php on line 15 array(9) { ["FileName"]=> string(8) "gen.tiff" ["FileDateTime"]=> int(1471921626) ["FileSize"]=> int(214) ["FileType"]=> int(7) ["MimeType"]=> string(10) "image/tiff" ["SectionsFound"]=> string(30) "ANY_TAG, IFD0, THUMBNAIL, EXIF" ["COMPUTED"]=> array(9) { ["html"]=> string(24) "width="128" height="132"" ["Height"]=> int(132) ["Width"]=> int(128) ["IsColor"]=> int(0) ["ByteOrderMotorola"]=> int(0) ["Thumbnail.FileType"]=> int(2) ["Thumbnail.MimeType"]=> string(10) "image/jpeg" ["Thumbnail.Height"]=> int(132) ["Thumbnail.Width"]=> int(128) } ["XResolution"]=> string(16) "8388608/16842752" ["THUMBNAIL"]=> array(5) { ["ImageWidth"]=> int(128) ["ImageLength"]=> int(132) ["JPEGInterchangeFormat"]=> int(386) ["JPEGInterchangeFormatLength"]=> int(128) ["THUMBNAIL"]=> string(128) "�R��M" => leak leak } } 8052e6d14d7f0000000000000000 => (0x7f4dd1e65280) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72926&edit=1

« previous php.bugs (#203798) next »