Bug #77479 [NEW]: imagewbmp() segfaults with very large images
| From: | cmb@php.net | Date: | Thu, 17 Jan 2019 12:58:05 +0000 |
| Subject: | Bug #77479 [NEW]: imagewbmp() segfaults with very large images | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-219036@lists.php.net to get a copy of this message | ||
From: cmb
Operating system: *
PHP version: 7.1Git-2019-01-17 (Git)
Package: GD related
Bug Type: Bug
Bug description:imagewbmp() segfaults with very large images
Description:
------------
If very large images (i.e. >= 256 megapixels) are passed to
imagewbmp(), the function causes a segfault since createwbmp()[1]
fails, but gdImageWBMPCtx() continues after raising an error[2].
This issue does not affect upstream libgd, where this issue has
been fixed long ago with commit 46fd625[3].
It seems to me that this is a low security issue (maybe even no
security issue at all), since it makes no sense to have such large
WBMP images at all, and usually PHP's memory_limit is set low
enough to prevent to allocate such large images at all.
[1]
<https://github.com/php/php-src/blob/php-7.1.26/ext/gd/libgd/wbmp.c#L110-L140>
[2]
<https://github.com/php/php-src/blob/php-7.1.26/ext/gd/libgd/gd_wbmp.c#L100-L102>
[3]
<https://github.com/libgd/libgd/commit/46fd62585ecbced255193cd5fe964bc44eb137de>
Test script:
---------------
<?php
$im = imagecreate(40000, 20000);
imagecolorallocate($im, 0, 0, 0);
imagewbmp($im, __DIR__ . '/wbmp.wbmp');
echo "DONE\n";
Expected result:
----------------
Warning: imagewbmp(): gd warning: product of memory allocation
multiplication would exceed INT_MAX, failing operation gracefully
in %s on line %d
Warning: imagewbmp(): Could not create WBMP in %s on line %d
DONE
Actual result:
--------------
Warning: imagewbmp(): gd warning: product of memory allocation
multiplication would exceed INT_MAX, failing operation gracefully
in %s on line %d
Warning: imagewbmp(): Could not create WBMP in %s on line %d
Segmentation fault (core dumped)
--
Edit bug report at https://bugs.php.net/bug.php?id=77479&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77479&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77479&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77479&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=77479&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=77479&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=77479&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=77479&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=77479&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=77479&r=support
Expected behavior: https://bugs.php.net/fix.php?id=77479&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=77479&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=77479&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=77479&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77479&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=77479&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=77479&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=77479&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77479&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=77479&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=77479&r=mysqlcfg