Bug #73213 [Asn->Csd]: Integer overflow in imageline() with antialiasing
| From: | cmb@php.net | Date: | Fri, 30 Sep 2016 22:08:31 +0000 |
| Subject: | Bug #73213 [Asn->Csd]: Integer overflow in imageline() with antialiasing | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204382@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73213&edit=1
ID: 73213
Updated by: cmb@php.net
Reported by: cmb@php.net
Summary: Integer overflow in imageline() with antialiasing
-Status: Assigned
+Status: Closed
Type: Bug
Package: GD related
Operating System: 32bit,LLP64
PHP Version: 5.6.26
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb
Revision: http://git.php.net/?p=php-src.git;a=commit;h=9acfb1a3a5268febb123b7e5fbd4eaf072c83537
Log: Fix #73213: Integer overflow in imageline() with antialiasing
Previous Comments:
------------------------------------------------------------------------
[2016-09-30 20:52:26] cmb@php.net
Description:
------------
Drawing very large antialised lines causes integer overflows in
gdImageAALine(), what can lead to strange results and even
crashes.
This issue had been reported upstream as
<https://github.com/libgd/libgd/issues/5> and
fixed, but the fix
didn't yet make it to PHP's bundled libgd.
Test script:
---------------
<?php
$im = imagecreatetruecolor(32768, 1);
$black = imagecolorallocate($im, 0, 0, 0);
imageantialias($im, true);
imageline($im, 0,0, 32767,0, $black);
imagepng($im, __DIR__ . DIRECTORY_SEPARATOR . 'aa-bug.png');
Expected result:
----------------
A PNG image with a line.
Actual result:
--------------
PHP crashes.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73213&edit=1