Sec Bug->Bug #73549 [Ana]: Use after free when stream is passed to imagepng

From: Date: Sun, 27 Nov 2016 22:54:51 +0000
Subject: Sec Bug->Bug #73549 [Ana]: Use after free when stream is passed to imagepng
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205664@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73549&edit=1 ID: 73549 Updated by: stas@php.net Reported by: marceloje at gmail dot com Summary: Use after free when stream is passed to imagepng Status: Analyzed -Type: Security +Type: Bug Package: GD related Operating System: Linux x86_64 -PHP Version: 7.0.13 +PHP Version: 5.6.28 Assigned To: cmb Block user comment: N Private report: Y Previous Comments: ------------------------------------------------------------------------ [2016-11-27 22:49:41] stas@php.net My bad, it works. ------------------------------------------------------------------------ [2016-11-27 11:06:56] cmb@php.net I've just applied the patch against current PHP-5.6 head, and the test succeeds. The test failure you're getting is expected *without* the patch. Note that there's a build flaw in ext/gd where changes to gd_ctx.c (and other source files) don't trigger re-compilation of gd.(l)o. In other words, if you already have built PHP-5.6, apply the patch and do only make, the test failure is to be expected. ------------------------------------------------------------------------ [2016-11-26 22:54:37] stas@php.net For me the test does not work: 002+ resource(5) of type (Unknown) 002- resource(%d) of type (stream) Could you please check? ------------------------------------------------------------------------ [2016-11-17 13:00:19] cmb@php.net The following patch has been added/updated: Patch Name: fix-73549 Revision: 1479387619 URL: https://bugs.php.net/patch-display.php?bug=73549&patch=fix-73549&revision=1479387619 ------------------------------------------------------------------------ [2016-11-17 12:59:14] cmb@php.net This issue is not particularly related to "invalid files", but rather happens *always* when a stream is passed to one of the image output functions. As such, it might be regarded medium severity. Alternative test script: <?php $stream = fopen(__DIR__ . DIRECTORY_SEPARATOR . '73549.png', 'w'); $im = imagecreatetruecolor(100, 100); var_dump(imagepng($im, $stream)); var_dump($stream); This script shows, that imagepng() closes the supplied stream, what should, of course, not happen if a stream is supplied, but only if a filename is given (in which case the stream would have been opened by _php_image_output_ctx()). The attached patch (PHP-5.6) is supposed to fix the issue. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73549 -- Edit this bug report at https://bugs.php.net/bug.php?id=73549&edit=1

« previous php.bugs (#205664) next »