Bug #73893 [Asn->Csd]: A hidden danger of death cycle in a function of gd
| From: | cmb@php.net | Date: | Tue, 10 Jan 2017 19:03:05 +0000 |
| Subject: | Bug #73893 [Asn->Csd]: A hidden danger of death cycle in a function of gd | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206475@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73893&edit=1
ID: 73893
Updated by: cmb@php.net
Reported by: swjun1128 at 126 dot com
Summary: A hidden danger of death cycle in a function of gd
-Status: Assigned
+Status: Closed
Type: Bug
Package: GD related
Operating System: ALL
PHP Version: 7.0.14
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=15837bab8ce05ead227d654f0b7ed8f6a0a431d8
Log: Fix #73893: A hidden danger of death cycle in a function of gd
Previous Comments:
------------------------------------------------------------------------
[2017-01-10 18:21:53] cmb@php.net
Thanks for reporting the problem!
As gdImageRotate() isn't used by PHP, nor is it declared to be a
PHP_API, there is no vulnerability (besides that it might be
regarded a programming error to pass such large angles to it).
Nonetheless, I'm going to remove the unused gdImageRotate() and
gdImageRotate45() from the bundled libgd to prevent that they will
be used in the future.
They will also be removed in GD-2.2.4.
------------------------------------------------------------------------
[2017-01-09 02:54:11] swjun1128 at 126 dot com
Description:
------------
I find a hidden danger of death cycle in a function of gdï¼gdImageRotate in the file
gd_rotate.c. Although from the version 5.5.0 the function is changed to another
function:gdImageRotateInterpolated(not for the reason I proposed)ï¼but the original is not
deleted.So,I think it is a hidden danger of death cycle.
while (dAngle >= 360.0) {
dAngle -= 360.0;
}
dAngle is a double.When it is assigned a large floating point number e.g:1e20,the function goes to a
death cycle because 1e20-360.0=1e20ï¼
The following script only goes wrong in the version before 5.5.0.But I still think it is a hidden
danger since the function gdï¼gdImageRotate is not deleted.
Test script:
---------------
<?php
// File and rotation
$filename = 'dog.jpg';
$angle = 2e30;
$im = imagecreatefromjpeg($filename);
// Content type
header('Content-type: image/jpeg');
// Load
$source = imagecreatefromjpeg($filename);
// Rotate
$rotate = imagerotate($source, $angle, 0);
// Output
imagejpeg($rotate,'dogrotate.jpg');
imagejpeg($source);
?>
Expected result:
----------------
Rotate the image with right angle.
Actual result:
--------------
death cycle
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73893&edit=1