Bug #77479 [Asn->Csd]: imagewbmp() segfaults with very large images
| From: | cmb@php.net | Date: | Sat, 19 Jan 2019 09:19:47 +0000 |
| Subject: | Bug #77479 [Asn->Csd]: imagewbmp() segfaults with very large images | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-219081@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77479&edit=1
ID: 77479
Updated by: cmb@php.net
Reported by: cmb@php.net
Summary: imagewbmp() segfaults with very large images
-Status: Assigned
+Status: Closed
Type: Bug
Package: GD related
Operating System: *
PHP Version: 7.1Git-2019-01-17 (Git)
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=44fa0b0f311beee4bfcbdb954d61f0c9a8395a96
Log: Fix #77479: imagewbmp() segfaults with very large images
Previous Comments:
------------------------------------------------------------------------
[2019-01-18 20:05:44] stas@php.net
Doesn't look like security issue - requires explicit user action with specially crafted
parameters to trigger the problem.
------------------------------------------------------------------------
[2019-01-18 13:53:04] cmb@php.net
To clarify: the segfault occurs *before* imagewbmp() outputs
anything.
Also, I have some doubts that imagewbmp() is actually still in use
anywhere, since it only makes sense for ancient devices (for
somewhat contemporary devices PNG is way better, and even GIF is
still superior).
------------------------------------------------------------------------
[2019-01-18 02:20:19] pajoye@php.net
thanks for the cath up, I must have missed this merge back then.
Afair we consider DDOS as security issue while 256M pixels will require quite some network to
achieve it :)
------------------------------------------------------------------------
[2019-01-17 13:15:19] cmb@php.net
<https://gist.github.com/cmb69/67e7e1658e1fb434452e96b377e7da54>
fixes the issue.
Stas, please assess whether this ticket has to kept private; if
not, please assign to me.
------------------------------------------------------------------------
[2019-01-17 12:58:05] cmb@php.net
Description:
------------
If very large images (i.e. >= 256 megapixels) are passed to
imagewbmp(), the function causes a segfault since createwbmp()[1]
fails, but gdImageWBMPCtx() continues after raising an error[2].
This issue does not affect upstream libgd, where this issue has
been fixed long ago with commit 46fd625[3].
It seems to me that this is a low security issue (maybe even no
security issue at all), since it makes no sense to have such large
WBMP images at all, and usually PHP's memory_limit is set low
enough to prevent to allocate such large images at all.
[1] <https://github.com/php/php-src/blob/php-7.1.26/ext/gd/libgd/wbmp.c#L110-L140>
[2] <https://github.com/php/php-src/blob/php-7.1.26/ext/gd/libgd/gd_wbmp.c#L100-L102>
[3] <https://github.com/libgd/libgd/commit/46fd62585ecbced255193cd5fe964bc44eb137de>
Test script:
---------------
<?php
$im = imagecreate(40000, 20000);
imagecolorallocate($im, 0, 0, 0);
imagewbmp($im, __DIR__ . '/wbmp.wbmp');
echo "DONE\n";
Expected result:
----------------
Warning: imagewbmp(): gd warning: product of memory allocation multiplication would exceed INT_MAX,
failing operation gracefully
in %s on line %d
Warning: imagewbmp(): Could not create WBMP in %s on line %d
DONE
Actual result:
--------------
Warning: imagewbmp(): gd warning: product of memory allocation multiplication would exceed INT_MAX,
failing operation gracefully
in %s on line %d
Warning: imagewbmp(): Could not create WBMP in %s on line %d
Segmentation fault (core dumped)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77479&edit=1