Bug #77831 [NEW]: Heap-buffer-overflow in exif_iif_add_value in EXIF
| From: | stas@php.net | Date: | Tue, 02 Apr 2019 06:44:46 +0000 |
| Subject: | Bug #77831 [NEW]: Heap-buffer-overflow in exif_iif_add_value in EXIF | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-220285@lists.php.net to get a copy of this message | ||
From: stas
Operating system: *
PHP version: 7.1.27
Package: EXIF related
Bug Type: Bug
Bug description:Heap-buffer-overflow in exif_iif_add_value in EXIF
Description:
------------
Another OSS-Fuzz bug:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13938
Backtrace:
==1==ERROR: AddressSanitizer: heap-buffer-overflow on address
0x60400002cb7a at pc 0x00000071d6bb bp 0x7ffdd43127c0 sp 0x7ffdd43127b8
READ of size 8 at 0x60400002cb7a thread T0
SCARINESS: 23 (8-byte-read-heap-buffer-overflow)
#0 0x71d6ba in exif_iif_add_value php-src/ext/exif/exif.c:2158:23
#1 0x71144f in exif_iif_add_tag php-src/ext/exif/exif.c:2173:2
#2 0x718c3f in exif_process_IFD_TAG php-src/ext/exif/exif.c:3530:2
#3 0x7171e8 in exif_process_IFD_in_JPEG
php-src/ext/exif/exif.c:3563:8
#4 0x716e92 in exif_process_TIFF_in_JPEG
php-src/ext/exif/exif.c:3652:2
#5 0x714b87 in exif_scan_JPEG_header php-src/ext/exif/exif.c:3822:6
#6 0x714417 in exif_scan_FILE_header php-src/ext/exif/exif.c:4215:8
#7 0x713df7 in exif_read_from_impl php-src/ext/exif/exif.c:4356:8
#8 0x710139 in exif_read_from_file php-src/ext/exif/exif.c:4400:8
#9 0x70e842 in zif_exif_read_data php-src/ext/exif/exif.c:4473:9
#10 0xcd44c1 in zend_call_function
php-src/Zend/zend_execute_API.c:790:4
#11 0xcd31c9 in _call_user_function_ex
php-src/Zend/zend_execute_API.c:627:9
#12 0xfded5d in fuzzer_call_php_func_zval
php-src/sapi/fuzzer/fuzzer-sapi.c:222:11
#13 0xfdf0fc in fuzzer_call_php_func
php-src/sapi/fuzzer/fuzzer-sapi.c:244:2
#14 0xfde05b in LLVMFuzzerTestOneInput
php-src/sapi/fuzzer/fuzzer-exif.c:50:2
#15 0xfe11aa in ExecuteFilesOnyByOne(int, char**)
/src/libfuzzer/afl/afl_driver.cpp:156:5
#16 0xfe1411 in main /src/libfuzzer/afl/afl_driver.cpp:193:12
#17 0x7f216285b82f in __libc_start_main
/build/glibc-Cl5G7W/glibc-2.23/csu/libc-start.c:291
#18 0x4640a8 in _start
0x60400002cb7f is located 0 bytes to the right of 47-byte region
[0x60400002cb50,0x60400002cb7f)
allocated by thread T0 here:
#0 0x4f6f62 in malloc _asan_rtl_
#1 0xc8518d in __zend_malloc php-src/Zend/zend_alloc.c:2937:14
#2 0x7168a6 in exif_file_sections_add
php-src/ext/exif/exif.c:1988:10
#3 0x7149f8 in exif_scan_JPEG_header php-src/ext/exif/exif.c:3776:8
#4 0x714417 in exif_scan_FILE_header php-src/ext/exif/exif.c:4215:8
#5 0x713df7 in exif_read_from_impl php-src/ext/exif/exif.c:4356:8
#6 0x710139 in exif_read_from_file php-src/ext/exif/exif.c:4400:8
#7 0x70e842 in zif_exif_read_data php-src/ext/exif/exif.c:4473:9
#8 0xcd44c1 in zend_call_function
php-src/Zend/zend_execute_API.c:790:4
#9 0xcd31c9 in _call_user_function_ex
php-src/Zend/zend_execute_API.c:627:9
#10 0xfded5d in fuzzer_call_php_func_zval
php-src/sapi/fuzzer/fuzzer-sapi.c:222:11
#11 0xfdf0fc in fuzzer_call_php_func
php-src/sapi/fuzzer/fuzzer-sapi.c:244:2
#12 0xfde05b in LLVMFuzzerTestOneInput
php-src/sapi/fuzzer/fuzzer-exif.c:50:2
#13 0xfe11aa in ExecuteFilesOnyByOne(int, char**)
/src/libfuzzer/afl/afl_driver.cpp:156:5
#14 0xfe1411 in main /src/libfuzzer/afl/afl_driver.cpp:193:12
#15 0x7f216285b82f in __libc_start_main
/build/glibc-Cl5G7W/glibc-2.23/csu/libc-start.c:291
--
Edit bug report at https://bugs.php.net/bug.php?id=77831&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77831&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77831&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77831&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=77831&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=77831&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=77831&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=77831&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=77831&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=77831&r=support
Expected behavior: https://bugs.php.net/fix.php?id=77831&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=77831&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=77831&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=77831&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77831&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=77831&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=77831&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=77831&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=77831&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=77831&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=77831&r=mysqlcfg