Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions NEWS
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,10 @@ PHP NEWS
. Fixed bug GH-23120 (Stack overflow when comparing deeply nested DOM nodes
with DOMNode::isEqualNode()). (Weilin Du)

- Exif:
. Fixed exif_read_data() allocating a HEIF meta box larger than the file
it came from. (iliaal)

- Intl:
. Fixed IntlListFormatter::__construct() leaving stale global error state
after successful calls. (Weilin Du)
Expand Down
2 changes: 1 addition & 1 deletion ext/exif/exif.c
Original file line number Diff line number Diff line change
Expand Up @@ -4415,7 +4415,7 @@ static bool exif_scan_HEIF_header(image_info_type *ImageInfo, unsigned char *buf
}
if (box.type == FOURCC("meta")) {
limit = box.size - box_header_size;
if (limit < 36) {
if (limit < 36 || limit > ImageInfo->FileSize) {
break;
}
data = (unsigned char *)emalloc(limit);
Expand Down
23 changes: 23 additions & 0 deletions ext/exif/tests/heic_meta_box_alloc.phpt
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
--TEST--
HEIC meta box size must be bounded by the file size
--EXTENSIONS--
exif
--INI--
memory_limit=32M
--FILE--
<?php
// ftyp box (size 20) followed by a meta box whose size field claims 128MB,
// in a file that is only 37 bytes. Without an upper bound the meta box
// allocation exhausts memory_limit before any read is attempted.
$ftyp = pack("N", 20) . "ftypheic" . str_repeat("\x00", 8);
$meta = pack("N", 0x08000000) . "meta" . str_repeat("\x00", 8);
file_put_contents(__DIR__."/heic_meta_box_alloc.heic", $ftyp . $meta . "\x00");
var_dump(exif_read_data(__DIR__."/heic_meta_box_alloc.heic"));
?>
--CLEAN--
<?php
@unlink(__DIR__."/heic_meta_box_alloc.heic");
?>
--EXPECTF--
Warning: exif_read_data(heic_meta_box_alloc.heic): Invalid HEIF file in %s on line %d
bool(false)
Loading