Bug #73213 [Asn->Csd]: Integer overflow in imageline() with antialiasing

From: Date: Fri, 30 Sep 2016 22:08:31 +0000
Subject: Bug #73213 [Asn->Csd]: Integer overflow in imageline() with antialiasing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204382@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73213&edit=1 ID: 73213 Updated by: cmb@php.net Reported by: cmb@php.net Summary: Integer overflow in imageline() with antialiasing -Status: Assigned +Status: Closed Type: Bug Package: GD related Operating System: 32bit,LLP64 PHP Version: 5.6.26 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb Revision: http://git.php.net/?p=php-src.git;a=commit;h=9acfb1a3a5268febb123b7e5fbd4eaf072c83537 Log: Fix #73213: Integer overflow in imageline() with antialiasing Previous Comments: ------------------------------------------------------------------------ [2016-09-30 20:52:26] cmb@php.net Description: ------------ Drawing very large antialised lines causes integer overflows in gdImageAALine(), what can lead to strange results and even crashes. This issue had been reported upstream as <https://github.com/libgd/libgd/issues/5> and fixed, but the fix didn't yet make it to PHP's bundled libgd. Test script: --------------- <?php $im = imagecreatetruecolor(32768, 1); $black = imagecolorallocate($im, 0, 0, 0); imageantialias($im, true); imageline($im, 0,0, 32767,0, $black); imagepng($im, __DIR__ . DIRECTORY_SEPARATOR . 'aa-bug.png'); Expected result: ---------------- A PNG image with a line. Actual result: -------------- PHP crashes. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73213&edit=1

« previous php.bugs (#204382) next »