Sec Bug->Bug #77479 [Asn]: imagewbmp() segfaults with very large images

From: Date: Fri, 18 Jan 2019 20:05:44 +0000
Subject: Sec Bug->Bug #77479 [Asn]: imagewbmp() segfaults with very large images
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219070@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77479&edit=1 ID: 77479 Updated by: stas@php.net Reported by: cmb@php.net Summary: imagewbmp() segfaults with very large images Status: Assigned -Type: Security +Type: Bug Package: GD related Operating System: * PHP Version: 7.1Git-2019-01-17 (Git) -Assigned To: stas +Assigned To: cmb Block user comment: N Private report: Y New Comment: Doesn't look like security issue - requires explicit user action with specially crafted parameters to trigger the problem. Previous Comments: ------------------------------------------------------------------------ [2019-01-18 13:53:04] cmb@php.net To clarify: the segfault occurs *before* imagewbmp() outputs anything. Also, I have some doubts that imagewbmp() is actually still in use anywhere, since it only makes sense for ancient devices (for somewhat contemporary devices PNG is way better, and even GIF is still superior). ------------------------------------------------------------------------ [2019-01-18 02:20:19] pajoye@php.net thanks for the cath up, I must have missed this merge back then. Afair we consider DDOS as security issue while 256M pixels will require quite some network to achieve it :) ------------------------------------------------------------------------ [2019-01-17 13:15:19] cmb@php.net <https://gist.github.com/cmb69/67e7e1658e1fb434452e96b377e7da54> fixes the issue. Stas, please assess whether this ticket has to kept private; if not, please assign to me. ------------------------------------------------------------------------ [2019-01-17 12:58:05] cmb@php.net Description: ------------ If very large images (i.e. >= 256 megapixels) are passed to imagewbmp(), the function causes a segfault since createwbmp()[1] fails, but gdImageWBMPCtx() continues after raising an error[2]. This issue does not affect upstream libgd, where this issue has been fixed long ago with commit 46fd625[3]. It seems to me that this is a low security issue (maybe even no security issue at all), since it makes no sense to have such large WBMP images at all, and usually PHP's memory_limit is set low enough to prevent to allocate such large images at all. [1] <https://github.com/php/php-src/blob/php-7.1.26/ext/gd/libgd/wbmp.c#L110-L140> [2] <https://github.com/php/php-src/blob/php-7.1.26/ext/gd/libgd/gd_wbmp.c#L100-L102> [3] <https://github.com/libgd/libgd/commit/46fd62585ecbced255193cd5fe964bc44eb137de> Test script: --------------- <?php $im = imagecreate(40000, 20000); imagecolorallocate($im, 0, 0, 0); imagewbmp($im, __DIR__ . '/wbmp.wbmp'); echo "DONE\n"; Expected result: ---------------- Warning: imagewbmp(): gd warning: product of memory allocation multiplication would exceed INT_MAX, failing operation gracefully in %s on line %d Warning: imagewbmp(): Could not create WBMP in %s on line %d DONE Actual result: -------------- Warning: imagewbmp(): gd warning: product of memory allocation multiplication would exceed INT_MAX, failing operation gracefully in %s on line %d Warning: imagewbmp(): Could not create WBMP in %s on line %d Segmentation fault (core dumped) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77479&edit=1

« previous php.bugs (#219070) next »