Bug #73957 [Asn->Csd]: signed integer conversion in imagescale()
| From: | cmb@php.net | Date: | Fri, 09 Mar 2018 23:38:13 +0000 |
| Subject: | Bug #73957 [Asn->Csd]: signed integer conversion in imagescale() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214257@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73957&edit=1
ID: 73957
Updated by: cmb@php.net
Reported by: cmb@php.net
Summary: signed integer conversion in imagescale()
-Status: Assigned
+Status: Closed
Type: Bug
Package: GD related
Operating System: *
PHP Version: 7.0.15RC1
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=f1b358c9a928e28e58bb23c5d5baa723df4638e0
Log: Fix #73957: signed integer conversion in imagescale()
Previous Comments:
------------------------------------------------------------------------
[2017-01-18 19:11:55] cmb@php.net
Description:
------------
The int parameters given to imagescale() are converted from
zend_long to int without checking their range[1]. This allows for
silent truncation, and even worse, the result of signed integer
conversion is unspecified if the value cannot be represented by
the target type.
[1] <https://github.com/php/php-src/blob/PHP-7.0.15/ext/gd/gd.c#L4691-L4725>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73957&edit=1