Bug #72926 [Opn]: Uninitialized Thumbail Data Leads To Memory Leakage in exif_process_IFD_in_TIFF
| From: | nguyenvuhoang199321 at gmail dot com | Date: | Mon, 05 Sep 2016 06:45:04 +0000 |
| Subject: | Bug #72926 [Opn]: Uninitialized Thumbail Data Leads To Memory Leakage in exif_process_IFD_in_TIFF | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203798@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72926&edit=1
ID: 72926
User updated by: nguyenvuhoang199321 at gmail dot com
Reported by: nguyenvuhoang199321 at gmail dot com
Summary: Uninitialized Thumbail Data Leads To Memory Leakage
in exif_process_IFD_in_TIFF
Status: Open
Type: Bug
Package: EXIF related
Operating System: ALL
PHP Version: 5.6.26
Block user comment: N
Private report: N
New Comment:
I think it is still security issue. Because, it will lead to memory leakage.
Previous Comments:
------------------------------------------------------------------------
[2016-09-05 04:00:12] stas@php.net
Same issue as 72627, now fixed in both places.
------------------------------------------------------------------------
[2016-08-23 03:19:19] nguyenvuhoang199321 at gmail dot com
Description:
------------
I found other code chunk that leads to memory leakage.
```
exif_process_IFD_in_TIFF(ImageInfo, entry_offset, sub_section_index);
if (section_index!=SECTION_THUMBNAIL && entry_tag==TAG_SUB_IFD) {
if (ImageInfo->Thumbnail.filetype != IMAGE_FILETYPE_UNKNOWN
&& ImageInfo->Thumbnail.size
&& ImageInfo->Thumbnail.offset
&& ImageInfo->read_thumbnail
) {
#ifdef EXIF_DEBUG
exif_error_docref(NULL EXIFERR_CC, ImageInfo, E_NOTICE, "%s THUMBNAIL @0x%04X +
0x%04X", ImageInfo->Thumbnail.data ? "Ignore" : "Read",
ImageInfo->Thumbnail.offset, ImageInfo->Thumbnail.size);
#endif
if (!ImageInfo->Thumbnail.data) {
ImageInfo->Thumbnail.data = safe_emalloc(ImageInfo->Thumbnail.size, 1, 0);
php_stream_seek(ImageInfo->infile, ImageInfo->Thumbnail.offset, SEEK_SET);
fgot = php_stream_read(ImageInfo->infile, ImageInfo->Thumbnail.data,
ImageInfo->Thumbnail.size);
if (fgot < ImageInfo->Thumbnail.size) {
EXIF_ERRLOG_THUMBEOF(ImageInfo)
}
exif_thumbnail_build(ImageInfo);
}
}
}
```
As you can see this code is processing SUB_IFD_TAG and not verify offset of Thumbnail data. Because
lack of checking ImageInfo->Thumbnail.offset if an attack set ImageInfo->Thumbnail.offset
larger than ImageInfo->FileSize then *php_stream_read* return 0 to fgot, because
EXIF_ERRLOG_THUMBEOF was defined as :
```
#define EXIF_ERRLOG_THUMBEOF(ImageInfo) exif_error_docref(NULL EXIFERR_CC, ImageInfo, E_WARNING,
"%s", EXIF_ERROR_THUMBEOF);
```
As you can see there is no exit after this error is output.
This bug does same problem with this bug i reported before https://bugs.php.net/bug.php?id=72627
Here tiff file : https://drive.google.com/file/d/0B0D1DYQpkA9USUt4c2ZBT21SWE0/view?usp=sharing
Test script:
---------------
<?php
$exif = exif_read_data('exif/gen.tiff',0,0,true);
var_dump($exif);
$thumb = $exif['THUMBNAIL']['THUMBNAIL'];
echo bin2hex($thumb);
?>
Actual result:
--------------
PHP Warning: exif_read_data(gen.tiff): Error in TIFF: filesize(x00D6) less than size of IFD
dir(x0FA0) in /vagrant_extend/audit/exif.php on line 15
Warning: exif_read_data(gen.tiff): Error in TIFF: filesize(x00D6) less than size of IFD dir(x0FA0)
in /vagrant_extend/audit/exif.php on line 15
PHP Warning: exif_read_data(gen.tiff): Thumbnail goes IFD boundary or end of file reached in
/vagrant_extend/audit/exif.php on line 15
Warning: exif_read_data(gen.tiff): Thumbnail goes IFD boundary or end of file reached in
/vagrant_extend/audit/exif.php on line 15
PHP Warning: exif_read_data(gen.tiff): Error in TIFF: filesize(x00D6) less than start of IFD
dir(x829A0004) in /vagrant_extend/audit/exif.php on line 15
Warning: exif_read_data(gen.tiff): Error in TIFF: filesize(x00D6) less than start of IFD
dir(x829A0004) in /vagrant_extend/audit/exif.php on line 15
array(9) {
["FileName"]=>
string(8) "gen.tiff"
["FileDateTime"]=>
int(1471921626)
["FileSize"]=>
int(214)
["FileType"]=>
int(7)
["MimeType"]=>
string(10) "image/tiff"
["SectionsFound"]=>
string(30) "ANY_TAG, IFD0, THUMBNAIL, EXIF"
["COMPUTED"]=>
array(9) {
["html"]=>
string(24) "width="128" height="132""
["Height"]=>
int(132)
["Width"]=>
int(128)
["IsColor"]=>
int(0)
["ByteOrderMotorola"]=>
int(0)
["Thumbnail.FileType"]=>
int(2)
["Thumbnail.MimeType"]=>
string(10) "image/jpeg"
["Thumbnail.Height"]=>
int(132)
["Thumbnail.Width"]=>
int(128)
}
["XResolution"]=>
string(16) "8388608/16842752"
["THUMBNAIL"]=>
array(5) {
["ImageWidth"]=>
int(128)
["ImageLength"]=>
int(132)
["JPEGInterchangeFormat"]=>
int(386)
["JPEGInterchangeFormatLength"]=>
int(128)
["THUMBNAIL"]=>
string(128) "�R��M" => leak leak
}
}
8052e6d14d7f0000000000000000 => (0x7f4dd1e65280)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72926&edit=1