Bug #76041 [Com]: null pointer access crashed php

From: Date: Fri, 02 Mar 2018 08:24:32 +0000
Subject: Bug #76041 [Com]: null pointer access crashed php
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214174@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76041&edit=1 ID: 76041 Comment by: jianjia11010 at hotmail dot com Reported by: jianjia11010 at hotmail dot com Summary: null pointer access crashed php Status: Open Type: Bug Package: GD related PHP Version: 7.2.3 Block user comment: N Private report: N New Comment: In theory, if someone set the parameter intentional to access some address contains a vaild pointer to another writeable location, then the memory CAN BE OVERWRITTEN TO ANYTHING. For example: On a 32bit machine, Addr 0xC0F000=0x1F00000, Addr 0x1F00000 is writtable, then if do: imagecreate((0xC0F000>>2)+1),1); imageantialias($im,true); imageline($im,0,(0xC0F000>>2),0,(0xC0F000>>2),(int)0x12345678); After then, the content of 0x1F00000 would be 0x12345678. So, this bug does contain a security risk. Previous Comments: ------------------------------------------------------------------------ [2018-03-02 02:38:32] jianjia11010 at hotmail dot com Description: ------------ I've tested 7.1.x,7.0.x , it's ok. When php 7.2.x, it crashed. The problem is when image resource created by imagecreate function which is not truecolor will treat as truecolor in gdImageSetAAPixelColor function when antialias option is on even 'im->tpixels' is null. gd.c:1230:gdImageSetAAPixelColor: im->tpixels[y][x]=gdTrueColorAlpha(dr, dg, db, gdAlphaOpaque); Test script: --------------- <?php $im=imagecreate(100,100); imageantialias($im,true); imageline($im,0,0,10,10,0xffffff); Expected result: ---------------- The php process crashed immediately. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76041&edit=1

« previous php.bugs (#214174) next »