Bug #77831 [NEW]: Heap-buffer-overflow in exif_iif_add_value in EXIF

From: Date: Tue, 02 Apr 2019 06:44:46 +0000
Subject: Bug #77831 [NEW]: Heap-buffer-overflow in exif_iif_add_value in EXIF
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-220285@lists.php.net to get a copy of this message
From: stas Operating system: * PHP version: 7.1.27 Package: EXIF related Bug Type: Bug Bug description:Heap-buffer-overflow in exif_iif_add_value in EXIF Description: ------------ Another OSS-Fuzz bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13938 Backtrace: ==1==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x60400002cb7a at pc 0x00000071d6bb bp 0x7ffdd43127c0 sp 0x7ffdd43127b8 READ of size 8 at 0x60400002cb7a thread T0 SCARINESS: 23 (8-byte-read-heap-buffer-overflow) #0 0x71d6ba in exif_iif_add_value php-src/ext/exif/exif.c:2158:23 #1 0x71144f in exif_iif_add_tag php-src/ext/exif/exif.c:2173:2 #2 0x718c3f in exif_process_IFD_TAG php-src/ext/exif/exif.c:3530:2 #3 0x7171e8 in exif_process_IFD_in_JPEG php-src/ext/exif/exif.c:3563:8 #4 0x716e92 in exif_process_TIFF_in_JPEG php-src/ext/exif/exif.c:3652:2 #5 0x714b87 in exif_scan_JPEG_header php-src/ext/exif/exif.c:3822:6 #6 0x714417 in exif_scan_FILE_header php-src/ext/exif/exif.c:4215:8 #7 0x713df7 in exif_read_from_impl php-src/ext/exif/exif.c:4356:8 #8 0x710139 in exif_read_from_file php-src/ext/exif/exif.c:4400:8 #9 0x70e842 in zif_exif_read_data php-src/ext/exif/exif.c:4473:9 #10 0xcd44c1 in zend_call_function php-src/Zend/zend_execute_API.c:790:4 #11 0xcd31c9 in _call_user_function_ex php-src/Zend/zend_execute_API.c:627:9 #12 0xfded5d in fuzzer_call_php_func_zval php-src/sapi/fuzzer/fuzzer-sapi.c:222:11 #13 0xfdf0fc in fuzzer_call_php_func php-src/sapi/fuzzer/fuzzer-sapi.c:244:2 #14 0xfde05b in LLVMFuzzerTestOneInput php-src/sapi/fuzzer/fuzzer-exif.c:50:2 #15 0xfe11aa in ExecuteFilesOnyByOne(int, char**) /src/libfuzzer/afl/afl_driver.cpp:156:5 #16 0xfe1411 in main /src/libfuzzer/afl/afl_driver.cpp:193:12 #17 0x7f216285b82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/csu/libc-start.c:291 #18 0x4640a8 in _start 0x60400002cb7f is located 0 bytes to the right of 47-byte region [0x60400002cb50,0x60400002cb7f) allocated by thread T0 here: #0 0x4f6f62 in malloc _asan_rtl_ #1 0xc8518d in __zend_malloc php-src/Zend/zend_alloc.c:2937:14 #2 0x7168a6 in exif_file_sections_add php-src/ext/exif/exif.c:1988:10 #3 0x7149f8 in exif_scan_JPEG_header php-src/ext/exif/exif.c:3776:8 #4 0x714417 in exif_scan_FILE_header php-src/ext/exif/exif.c:4215:8 #5 0x713df7 in exif_read_from_impl php-src/ext/exif/exif.c:4356:8 #6 0x710139 in exif_read_from_file php-src/ext/exif/exif.c:4400:8 #7 0x70e842 in zif_exif_read_data php-src/ext/exif/exif.c:4473:9 #8 0xcd44c1 in zend_call_function php-src/Zend/zend_execute_API.c:790:4 #9 0xcd31c9 in _call_user_function_ex php-src/Zend/zend_execute_API.c:627:9 #10 0xfded5d in fuzzer_call_php_func_zval php-src/sapi/fuzzer/fuzzer-sapi.c:222:11 #11 0xfdf0fc in fuzzer_call_php_func php-src/sapi/fuzzer/fuzzer-sapi.c:244:2 #12 0xfde05b in LLVMFuzzerTestOneInput php-src/sapi/fuzzer/fuzzer-exif.c:50:2 #13 0xfe11aa in ExecuteFilesOnyByOne(int, char**) /src/libfuzzer/afl/afl_driver.cpp:156:5 #14 0xfe1411 in main /src/libfuzzer/afl/afl_driver.cpp:193:12 #15 0x7f216285b82f in __libc_start_main /build/glibc-Cl5G7W/glibc-2.23/csu/libc-start.c:291 -- Edit bug report at https://bugs.php.net/bug.php?id=77831&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77831&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77831&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77831&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=77831&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=77831&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=77831&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=77831&r=needscript Try newer version: https://bugs.php.net/fix.php?id=77831&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=77831&r=support Expected behavior: https://bugs.php.net/fix.php?id=77831&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=77831&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=77831&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=77831&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77831&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=77831&r=dst IIS Stability: https://bugs.php.net/fix.php?id=77831&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=77831&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=77831&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=77831&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=77831&r=mysqlcfg

« previous php.bugs (#220285) next »