Bug #73279 [Asn->Csd]: Integer overflow in gdImageScaleBilinearPalette()
| From: | cmb@php.net | Date: | Mon, 10 Oct 2016 10:18:04 +0000 |
| Subject: | Bug #73279 [Asn->Csd]: Integer overflow in gdImageScaleBilinearPalette() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204576@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73279&edit=1
ID: 73279
Updated by: cmb@php.net
Reported by: cmb@php.net
Summary: Integer overflow in gdImageScaleBilinearPalette()
-Status: Assigned
+Status: Closed
Type: Bug
Package: GD related
Operating System: *
PHP Version: 5.6Git-2016-10-10 (Git)
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=fc989fc6e773ccfb4d9ade0f466a3c5c2820bfdc
Log: Fix #73279: Integer overflow in gdImageScaleBilinearPalette()
Previous Comments:
------------------------------------------------------------------------
[2016-10-10 09:25:19] cmb@php.net
Description:
------------
On platforms where
char is actually signed char an integer
overflow can happen in gdImageScaleBilinearPalette due to sign
extension when red, green and blue are passed to
gdTrueColorAlpha().
This issue has been reported against upstream libgd[1], but as
PHP's bundled libgd is affected as well, I'm forwarding.
[1] <https://github.com/libgd/libgd/issues/330>
Test script:
---------------
<?php
$src = imagecreate(100, 100);
imagecolorallocate($src, 255, 255, 255);
$dst = imagescale($src, 200, 200, IMG_BILINEAR_FIXED);
printf("color: %x\n", imagecolorat($dst, 99, 99));
Expected result:
----------------
color: ffffff
Actual result:
--------------
color: fffffffffffefeff
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73279&edit=1