Sec Bug->Bug #73549 [Ana]: Use after free when stream is passed to imagepng
| From: | stas@php.net | Date: | Sun, 27 Nov 2016 22:54:51 +0000 |
| Subject: | Sec Bug->Bug #73549 [Ana]: Use after free when stream is passed to imagepng | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205664@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73549&edit=1
ID: 73549
Updated by: stas@php.net
Reported by: marceloje at gmail dot com
Summary: Use after free when stream is passed to imagepng
Status: Analyzed
-Type: Security
+Type: Bug
Package: GD related
Operating System: Linux x86_64
-PHP Version: 7.0.13
+PHP Version: 5.6.28
Assigned To: cmb
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2016-11-27 22:49:41] stas@php.net
My bad, it works.
------------------------------------------------------------------------
[2016-11-27 11:06:56] cmb@php.net
I've just applied the patch against current PHP-5.6 head, and the
test succeeds. The test failure you're getting is expected
*without* the patch.
Note that there's a build flaw in ext/gd where changes to gd_ctx.c
(and other source files) don't trigger re-compilation of gd.(l)o.
In other words, if you already have built PHP-5.6, apply the patch
and do only
make, the test failure is to be expected.
------------------------------------------------------------------------
[2016-11-26 22:54:37] stas@php.net
For me the test does not work:
002+ resource(5) of type (Unknown)
002- resource(%d) of type (stream)
Could you please check?
------------------------------------------------------------------------
[2016-11-17 13:00:19] cmb@php.net
The following patch has been added/updated:
Patch Name: fix-73549
Revision: 1479387619
URL: https://bugs.php.net/patch-display.php?bug=73549&patch=fix-73549&revision=1479387619
------------------------------------------------------------------------
[2016-11-17 12:59:14] cmb@php.net
This issue is not particularly related to "invalid files", but
rather happens *always* when a stream is passed to one of the
image output functions. As such, it might be regarded medium
severity.
Alternative test script:
<?php
$stream = fopen(__DIR__ . DIRECTORY_SEPARATOR . '73549.png', 'w');
$im = imagecreatetruecolor(100, 100);
var_dump(imagepng($im, $stream));
var_dump($stream);
This script shows, that imagepng() closes the supplied stream,
what should, of course, not happen if a stream is supplied, but
only if a filename is given (in which case the stream would have
been opened by _php_image_output_ctx()).
The attached patch (PHP-5.6) is supposed to fix the issue.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73549
--
Edit this bug report at https://bugs.php.net/bug.php?id=73549&edit=1