Sec Bug->Doc #75788 [Asn]: [FG-VD-18-005] PHP GD Denial of Service Vulnerability Notification
| From: | stas@php.net | Date: | Tue, 16 Jan 2018 20:06:00 +0000 |
| Subject: | Sec Bug->Doc #75788 [Asn]: [FG-VD-18-005] PHP GD Denial of Service Vulnerability Notification | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-15340@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75788&edit=1
ID: 75788
Updated by: stas@php.net
Reported by: zyyang at fortinet dot com
Summary: [FG-VD-18-005] PHP GD Denial of Service
Vulnerability Notification
Status: Assigned
-Type: Security
+Type: Documentation Problem
Package: GD related
Operating System: CentOS 6.8 x64
PHP Version: 5.6.33
Assigned To: cmb
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2018-01-16 17:44:37] zyyang at fortinet dot com
Hi,
In change log, can you add a short note like thanks for Zhouyuan Yang of Fortinet's FortiGuard
Labs?
------------------------------------------------------------------------
[2018-01-15 14:02:21] cmb@php.net
The documentation regarding this issue has been improved:
<http://svn.php.net/viewvc?view=revision&revision=343841>.
@zyyang Is that sufficient?
------------------------------------------------------------------------
[2018-01-11 23:44:13] zyyang at fortinet dot com
Great! Thanks for your time!
If there will be a note in the document, please let me know.
------------------------------------------------------------------------
[2018-01-11 23:40:05] stas@php.net
The software that uses only file size and the software that checks different values than it sends to
imagecopyresampled() should of course be fixed. But I am afraid we can't do much here to fix
it, that should be done by the developers of that software.
Since GIF can be not a single image but collection of images (e.g. animated GIFs), it is indeed a
good idea to document which of the sizes each function returns.
------------------------------------------------------------------------
[2018-01-11 23:36:37] zyyang at fortinet dot com
Good point.
But the issue is existing in a number of working PHP software, they all limited the file size and
file width & height to try to avoid this kind of attack. But for the file width & height,
some of them is getting from getimagesize(), some not.
I think we may consider adding a comment to the document, that the file width & height from the
function getimagesize() is not same as the file width & height shows in some other ways. And
when using the function imagecopyresampled(), it is preferred to get the image width and height
using the function getimagesize().
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=75788
--
Edit this bug report at https://bugs.php.net/bug.php?id=75788&edit=1