Repository navigation
Conversation
Problem: Potential conversion of a negative signed TIFF value to a large unsigned value when parsing image dimensions. Solution: Reject negative signed SHORT values before assigning them to the unsigned entry_value variable. Signed-off-by: Timofey Mishin <t.mishin@fobos-nt.ru> Signed-off-by: Georgij Tsarin <crystarm@altlinux.org>
Contributor
|
These values only end up in the array |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
php_handle_tiff() stores parsed TIFF values in the unsigned size_t variable entry_value. When processing TAG_FMT_SSHORT, a negative value returned by php_ifd_get16s() can be implicitly converted to a large unsigned value.
If the entry represents ImageWidth or ImageHeight, this value can then be assigned to the corresponding image dimension.
Solution
Check the signed SHORT value before converting it to size_t. Negative values are rejected with continue, so they are not assigned to entry_value and cannot be used as image dimensions.