Doc #75788 [Csd]: [FG-VD-18-005] PHP GD Denial of Service Vulnerability Notification

From: Date: Thu, 25 Jan 2018 21:11:06 +0000
Subject: Doc #75788 [Csd]: [FG-VD-18-005] PHP GD Denial of Service Vulnerability Notification
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-15363@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75788&edit=1 ID: 75788 User updated by: zyyang at fortinet dot com Reported by: zyyang at fortinet dot com Summary: [FG-VD-18-005] PHP GD Denial of Service Vulnerability Notification Status: Closed Type: Documentation Problem Package: GD related Operating System: CentOS 6.8 x64 PHP Version: 5.6.33 Assigned To: cmb Block user comment: N Private report: N New Comment: Another Ref: https://bugs.php.net/bug.php?id=75571 Previous Comments: ------------------------------------------------------------------------ [2018-01-25 18:39:08] cmb@php.net > For a program running on a web server, again, it could cause a > DoS attack. Indeed. The question is, however, whether this is something that has to be fixed in PHP or GD, or something that has to be fixed in respective userland code. I think it is the latter; otherwise PHP had to forbid recursive function calls or user input at all (see the third example of my former post). ------------------------------------------------------------------------ [2018-01-25 18:21:47] zyyang at fortinet dot com Hi, For a program running on a local host, it is not a security issue. Just some bad codes as you said. For a program running on a web server, again, it could cause a DoS attack. ------------------------------------------------------------------------ [2018-01-25 12:07:09] cmb@php.net On hindsight, I fail to see why bug #66387 has been treated as security issue for PHP/GD – actually, it would be only a security issue for userland code which allows to pass nonsensical values to a function. That's comparable to something like while ($_GET['foo']); or str_repeat('foo', $_GET['bar']); or function fac($n) { return $n > 1 ? $n * fac($n - 1) : 1; } echo fac($_GET['num']); ------------------------------------------------------------------------ [2018-01-25 01:46:37] zyyang at fortinet dot com Hi, I found a similar issue with this one. May help you reconsider it as a security issue, it happens on web servers and may let servers went down. https://bugs.php.net/bug.php?id=66387 https://github.com/libgd/libgd/issues/213 ------------------------------------------------------------------------ [2018-01-17 12:24:49] cmb@php.net > In change log, can you add a short note like thanks for Zhouyuan > Yang of Fortinet's FortiGuard Labs? Unfortunately, the SVN server is not configured to allow for prop changes. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75788 -- Edit this bug report at https://bugs.php.net/bug.php?id=75788&edit=1

« previous php.doc.bugs (#15363) next »