Bug #73638 [Opn->Nab]: Denial of Service in GD related

From: Date: Tue, 06 Dec 2016 08:24:44 +0000
Subject: Bug #73638 [Opn->Nab]: Denial of Service in GD related
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205799@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73638&edit=1 ID: 73638 Updated by: requinix@php.net Reported by: whitehat002 at hotmail dot com Summary: Denial of Service in GD related -Status: Open +Status: Not a bug Type: Bug Package: GD related Operating System: all PHP Version: 7.0.13 Block user comment: N Private report: N New Comment: Security bugs are about external users causing problems with code that has been otherwise written properly and safely. This code is (hypothetically) taking unverified input and performing an operation that necessarily uses system resources to complete, and PHP will dutifully attempt to execute it as it was written. It doesn't know that a string 99999999 bytes long is "too long" to render. The memory_limit would protect you from problems like this so don't set it to be unlimited. post_max_size will protect you from "large" request bodies so make sure that's set appropriately for your application. Finally and most importantly, you should always perform sanity checks - if not thorough validation - on user input before acting upon it. Previous Comments: ------------------------------------------------------------------------ [2016-12-06 06:48:27] whitehat002 at hotmail dot com The problem is not very determined, I was found through the black box testing. ------------------------------------------------------------------------ [2016-12-06 06:39:29] whitehat002 at hotmail dot com I mean I give in a huge string, CPU will be seriously consumed. Isn't it a security bug? ------------------------------------------------------------------------ [2016-12-06 05:57:53] stas@php.net Not sure where is the problem here. You're trying to render a huge string. It takes a long time. Where's the problem exactly? ------------------------------------------------------------------------ [2016-12-05 03:17:41] whitehat002 at hotmail dot com Why didn't people deal with the problem for a long time? ------------------------------------------------------------------------ [2016-12-02 02:27:55] whitehat002 at hotmail dot com array ImageTTFText(int im, int size, int angle, int x, int y, int col, string fontfile, string text); The parameter of vulnreability is string text. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73638 -- Edit this bug report at https://bugs.php.net/bug.php?id=73638&edit=1

« previous php.bugs (#205799) next »