#34042 [NEW]: Crash in imagettftext due to type overflow.

From: Date: Mon, 08 Aug 2005 18:49:33 +0000
Subject: #34042 [NEW]: Crash in imagettftext due to type overflow.
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-83200@lists.php.net to get a copy of this message
From: php at fiddaman dot net Operating system: Solaris 9 PHP version: 5.0.4 PHP Bug Type: GD related Bug description: Crash in imagettftext due to type overflow. Description: ------------ Same problem as bug #32893 (which was for PHP4). zend_parse_va_args is called with a template of "l" but a pointer to int which isn't large enough to hold the result. A patch which fixes this. --- ext/gd/gd.c~ 2005-05-01 11:36:21.134419000 +0000 +++ ext/gd/gd.c 2005-05-01 11:42:37.369849000 +0000 @@ -3017,7 +3017,8 @@ { zval *IM, *EXT = NULL; gdImagePtr im=NULL; - int col = -1, x = -1, y = -1, str_len, fontname_len, i, brect[8]; + long col = -1, x = -1, y = -1; + int str_len, fontname_len, i, brect[8]; double ptsize, angle; unsigned char *str = NULL, *fontname = NULL; char *error = NULL; Reproduce code: --------------- <?php $img = imagecreate(400, 70); imagettftext($img, 11/81*64, 0, 0, 27, 0, "/dev/null", "test"); ?> Actual result: -------------- 251 *p = Z_LVAL_PP(arg); (gdb) where #0 0x0000000100229e54 in zend_parse_va_args (num_args=4, type_spec=0x1002e4db3 "lllss|a", va=0xffffffff7fffea18, flags=0) at /spool/src/build/php-5.0.4/Zend/zend_API.c:251 #1 0x000000010022ac28 in zend_parse_parameters (num_args=8, type_spec=0x1002e4db0 "rddlllss|a") at /spool/src/build/php-5.0.4/Zend/zend_API.c:571 #2 0x000000010008f730 in php_imagettftext_common (ht=8, return_value=0x100796328, this_ptr=0x0, return_value_used=0, mode=0, extended=0) at /spool/src/build/php-5.0.4/ext/gd/gd.c:3134 #3 0x0000000100260468 in zend_do_fcall_common_helper ( execute_data=0xffffffff7fffef80, opline=0x10079d5a8, op_array=0x100798c08) at /spool/src/build/php-5.0.4/Zend/zend_execute.c:2727 #4 0x00000001002608d8 in zend_do_fcall_handler ( execute_data=0xffffffff7fffef80, opline=0x10079d5a8, op_array=0x100798c08) at /spool/src/build/php-5.0.4/Zend/zend_execute.c:2859 #5 0x000000010024ddec in execute (op_array=0x100798c08) at /spool/src/build/php-5.0.4/Zend/zend_execute.c:1406 #6 0x00000001002291f0 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /spool/src/build/php-5.0.4/Zend/zend.c:1069 #7 0x00000001001e8f90 in php_execute_script (primary_file=0xffffffff7ffffa80) at /spool/src/build/php-5.0.4/main/main.c:1632 #8 0x000000010026adb8 in main (argc=1, argv=0xffffffff7ffffb88) at /spool/src/build/php-5.0.4/sapi/cli/php_cli.c:946 -- Edit bug report at http://bugs.php.net/?id=34042&edit=1 -- Try a CVS snapshot (php4): http://bugs.php.net/fix.php?id=34042&r=trysnapshot4 Try a CVS snapshot (php5.0): http://bugs.php.net/fix.php?id=34042&r=trysnapshot50 Try a CVS snapshot (php5.1): http://bugs.php.net/fix.php?id=34042&r=trysnapshot51 Fixed in CVS: http://bugs.php.net/fix.php?id=34042&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=34042&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=34042&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=34042&r=needscript Try newer version: http://bugs.php.net/fix.php?id=34042&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=34042&r=support Expected behavior: http://bugs.php.net/fix.php?id=34042&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=34042&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=34042&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=34042&r=globals PHP 3 support discontinued: http://bugs.php.net/fix.php?id=34042&r=php3 Daylight Savings: http://bugs.php.net/fix.php?id=34042&r=dst IIS Stability: http://bugs.php.net/fix.php?id=34042&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=34042&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=34042&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=34042&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=34042&r=mysqlcfg

« previous php.bugs (#83200) next »