Bug #73893 [Asn->Csd]: A hidden danger of death cycle in a function of gd

From: Date: Tue, 10 Jan 2017 19:03:05 +0000
Subject: Bug #73893 [Asn->Csd]: A hidden danger of death cycle in a function of gd
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206475@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73893&edit=1 ID: 73893 Updated by: cmb@php.net Reported by: swjun1128 at 126 dot com Summary: A hidden danger of death cycle in a function of gd -Status: Assigned +Status: Closed Type: Bug Package: GD related Operating System: ALL PHP Version: 7.0.14 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=15837bab8ce05ead227d654f0b7ed8f6a0a431d8 Log: Fix #73893: A hidden danger of death cycle in a function of gd Previous Comments: ------------------------------------------------------------------------ [2017-01-10 18:21:53] cmb@php.net Thanks for reporting the problem! As gdImageRotate() isn't used by PHP, nor is it declared to be a PHP_API, there is no vulnerability (besides that it might be regarded a programming error to pass such large angles to it). Nonetheless, I'm going to remove the unused gdImageRotate() and gdImageRotate45() from the bundled libgd to prevent that they will be used in the future. They will also be removed in GD-2.2.4. ------------------------------------------------------------------------ [2017-01-09 02:54:11] swjun1128 at 126 dot com Description: ------------ I find a hidden danger of death cycle in a function of gd:gdImageRotate in the file gd_rotate.c. Although from the version 5.5.0 the function is changed to another function:gdImageRotateInterpolated(not for the reason I proposed),but the original is not deleted.So,I think it is a hidden danger of death cycle. while (dAngle >= 360.0) { dAngle -= 360.0; } dAngle is a double.When it is assigned a large floating point number e.g:1e20,the function goes to a death cycle because 1e20-360.0=1e20! The following script only goes wrong in the version before 5.5.0.But I still think it is a hidden danger since the function gd:gdImageRotate is not deleted. Test script: --------------- <?php // File and rotation $filename = 'dog.jpg'; $angle = 2e30; $im = imagecreatefromjpeg($filename); // Content type header('Content-type: image/jpeg'); // Load $source = imagecreatefromjpeg($filename); // Rotate $rotate = imagerotate($source, $angle, 0); // Output imagejpeg($rotate,'dogrotate.jpg'); imagejpeg($source); ?> Expected result: ---------------- Rotate the image with right angle. Actual result: -------------- death cycle ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73893&edit=1

« previous php.bugs (#206475) next »