Bug #73638 [Opn->Nab]: Denial of Service in GD related
| From: | requinix@php.net | Date: | Tue, 06 Dec 2016 08:24:44 +0000 |
| Subject: | Bug #73638 [Opn->Nab]: Denial of Service in GD related | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-205799@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73638&edit=1
ID: 73638
Updated by: requinix@php.net
Reported by: whitehat002 at hotmail dot com
Summary: Denial of Service in GD related
-Status: Open
+Status: Not a bug
Type: Bug
Package: GD related
Operating System: all
PHP Version: 7.0.13
Block user comment: N
Private report: N
New Comment:
Security bugs are about external users causing problems with code that has been otherwise written
properly and safely. This code is (hypothetically) taking unverified input and performing an
operation that necessarily uses system resources to complete, and PHP will dutifully attempt to
execute it as it was written. It doesn't know that a string 99999999 bytes long is "too
long" to render.
The memory_limit would protect you from problems like this so don't set it to be unlimited.
post_max_size will protect you from "large" request bodies so make sure that's set
appropriately for your application. Finally and most importantly, you should always perform sanity
checks - if not thorough validation - on user input before acting upon it.
Previous Comments:
------------------------------------------------------------------------
[2016-12-06 06:48:27] whitehat002 at hotmail dot com
The problem is not very determined, I was found through the black box testing.
------------------------------------------------------------------------
[2016-12-06 06:39:29] whitehat002 at hotmail dot com
I mean I give in a huge string, CPU will be seriously consumed. Isn't it a security bug?
------------------------------------------------------------------------
[2016-12-06 05:57:53] stas@php.net
Not sure where is the problem here. You're trying to render a huge string. It takes a long
time. Where's the problem exactly?
------------------------------------------------------------------------
[2016-12-05 03:17:41] whitehat002 at hotmail dot com
Why didn't people deal with the problem for a long time?
------------------------------------------------------------------------
[2016-12-02 02:27:55] whitehat002 at hotmail dot com
array ImageTTFText(int im, int size, int angle, int x, int y, int col, string fontfile, string
text);
The parameter of vulnreability is string text.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73638
--
Edit this bug report at https://bugs.php.net/bug.php?id=73638&edit=1