Sec Bug->Bug #77479 [Asn]: imagewbmp() segfaults with very large images
| From: | stas@php.net | Date: | Fri, 18 Jan 2019 20:05:44 +0000 |
| Subject: | Sec Bug->Bug #77479 [Asn]: imagewbmp() segfaults with very large images | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-219070@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77479&edit=1
ID: 77479
Updated by: stas@php.net
Reported by: cmb@php.net
Summary: imagewbmp() segfaults with very large images
Status: Assigned
-Type: Security
+Type: Bug
Package: GD related
Operating System: *
PHP Version: 7.1Git-2019-01-17 (Git)
-Assigned To: stas
+Assigned To: cmb
Block user comment: N
Private report: Y
New Comment:
Doesn't look like security issue - requires explicit user action with specially crafted
parameters to trigger the problem.
Previous Comments:
------------------------------------------------------------------------
[2019-01-18 13:53:04] cmb@php.net
To clarify: the segfault occurs *before* imagewbmp() outputs
anything.
Also, I have some doubts that imagewbmp() is actually still in use
anywhere, since it only makes sense for ancient devices (for
somewhat contemporary devices PNG is way better, and even GIF is
still superior).
------------------------------------------------------------------------
[2019-01-18 02:20:19] pajoye@php.net
thanks for the cath up, I must have missed this merge back then.
Afair we consider DDOS as security issue while 256M pixels will require quite some network to
achieve it :)
------------------------------------------------------------------------
[2019-01-17 13:15:19] cmb@php.net
<https://gist.github.com/cmb69/67e7e1658e1fb434452e96b377e7da54>
fixes the issue.
Stas, please assess whether this ticket has to kept private; if
not, please assign to me.
------------------------------------------------------------------------
[2019-01-17 12:58:05] cmb@php.net
Description:
------------
If very large images (i.e. >= 256 megapixels) are passed to
imagewbmp(), the function causes a segfault since createwbmp()[1]
fails, but gdImageWBMPCtx() continues after raising an error[2].
This issue does not affect upstream libgd, where this issue has
been fixed long ago with commit 46fd625[3].
It seems to me that this is a low security issue (maybe even no
security issue at all), since it makes no sense to have such large
WBMP images at all, and usually PHP's memory_limit is set low
enough to prevent to allocate such large images at all.
[1] <https://github.com/php/php-src/blob/php-7.1.26/ext/gd/libgd/wbmp.c#L110-L140>
[2] <https://github.com/php/php-src/blob/php-7.1.26/ext/gd/libgd/gd_wbmp.c#L100-L102>
[3] <https://github.com/libgd/libgd/commit/46fd62585ecbced255193cd5fe964bc44eb137de>
Test script:
---------------
<?php
$im = imagecreate(40000, 20000);
imagecolorallocate($im, 0, 0, 0);
imagewbmp($im, __DIR__ . '/wbmp.wbmp');
echo "DONE\n";
Expected result:
----------------
Warning: imagewbmp(): gd warning: product of memory allocation multiplication would exceed INT_MAX,
failing operation gracefully
in %s on line %d
Warning: imagewbmp(): Could not create WBMP in %s on line %d
DONE
Actual result:
--------------
Warning: imagewbmp(): gd warning: product of memory allocation multiplication would exceed INT_MAX,
failing operation gracefully
in %s on line %d
Warning: imagewbmp(): Could not create WBMP in %s on line %d
Segmentation fault (core dumped)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77479&edit=1