Description
Hi, It seemed to me that a negative signed value could potentially be converted to a large unsigned value here.
A potential signed-to-unsigned conversion issue exists in php_handle_tiff() when processing TIFF image dimensions.
The entry_value variable is declared as size_t, while the TAG_FMT_SSHORT case assigns the return value of php_ifd_get16s() to it:
case TAG_FMT_SSHORT:
entry_value = php_ifd_get16s(dir_entry+8, motorola_intel);
break;
php_ifd_get16s() returns a signed 16-bit value. Therefore, a negative value from the TIFF input can be converted to a large unsigned size_t value.
If such an entry is subsequently identified as TAG_IMAGEWIDTH or TAG_IMAGEHEIGHT, the converted value is assigned to width or height:
case TAG_IMAGEWIDTH:
case TAG_COMP_IMAGEWIDTH:
width = entry_value;
break;
case TAG_IMAGEHEIGHT:
case TAG_COMP_IMAGEHEIGHT:
height = entry_value;
break;
For example, a signed value of -1 can be converted to the maximum value of size_t instead of remaining negative.
According to the TIFF 6.0 specification, ImageWidth and ImageLength use the SHORT or LONG types, where SHORT is an unsigned 16-bit integer. The reader is expected to validate the field type.
Impact
A malformed TIFF containing a negative SSHORT value for an image dimension can therefore cause the parser to produce an unexpectedly large width or height.
Proposed solution
Validate the signed value before assigning it to the unsigned entry_value variable and reject negative values.
PHP Version
Operating System
Ubuntu 24.04
Description
Hi, It seemed to me that a negative signed value could potentially be converted to a large unsigned value here.
A potential signed-to-unsigned conversion issue exists in php_handle_tiff() when processing TIFF image dimensions.
The entry_value variable is declared as size_t, while the TAG_FMT_SSHORT case assigns the return value of php_ifd_get16s() to it:
case TAG_FMT_SSHORT:
entry_value = php_ifd_get16s(dir_entry+8, motorola_intel);
break;
php_ifd_get16s() returns a signed 16-bit value. Therefore, a negative value from the TIFF input can be converted to a large unsigned size_t value.
If such an entry is subsequently identified as TAG_IMAGEWIDTH or TAG_IMAGEHEIGHT, the converted value is assigned to width or height:
case TAG_IMAGEWIDTH:
case TAG_COMP_IMAGEWIDTH:
width = entry_value;
break;
case TAG_IMAGEHEIGHT:
case TAG_COMP_IMAGEHEIGHT:
height = entry_value;
break;
For example, a signed value of -1 can be converted to the maximum value of size_t instead of remaining negative.
According to the TIFF 6.0 specification, ImageWidth and ImageLength use the SHORT or LONG types, where SHORT is an unsigned 16-bit integer. The reader is expected to validate the field type.
Impact
A malformed TIFF containing a negative SSHORT value for an image dimension can therefore cause the parser to produce an unexpectedly large width or height.
Proposed solution
Validate the signed value before assigning it to the unsigned entry_value variable and reject negative values.
PHP Version
Operating System
Ubuntu 24.04