|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #79046 NaN to int cast undefined behavior in exif
Submitted: 2019-12-30 03:37 UTC Modified: 2019-12-30 15:29 UTC
From: wxhusst at gmail dot com Assigned:
Status: Closed Package: EXIF related
PHP Version: 7.4.1 OS: linux
Private report: No CVE-ID: None
 [2019-12-30 03:37 UTC] wxhusst at gmail dot com
exif_read_data may lead to integer overflow

raven@ubuntu ~/p/s/cli (master)> 
./php -r 'exif_read_data("/home/raven/php-src/crash-7cd841466926b2ce76d75b379568282a0fc8914b", "IFD0");'
/home/raven/php-src/ext/exif/exif.c:1677:10: runtime error: nan is outside the range of representable values of type 'unsigned long'
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior /home/raven/php-src/ext/exif/exif.c:1677:10 in

sorry,  no backtrace for gdb

the file

Test script:
./php -r 'exif_read_data("/home/raven/php-src/crash-7cd841466926b2ce76d75b379568282a0fc8914b", "IFD0");


Add a Patch

Pull Requests

Add a Pull Request


AllCommentsChangesGit/SVN commitsRelated reports
 [2019-12-30 15:29 UTC]
-Summary: UndefinedBehaviorSanitizer: undefined-behavior +Summary: NaN to int cast undefined behavior in exif -Status: Open +Status: Verified -Type: Security +Type: Bug
 [2019-12-30 15:29 UTC]
This was partially addressed in, but the NaN case wasn't handled.

Reclassifying as normal bug as this UBSan violation does not result in an actual miscompile.
 [2019-12-30 16:24 UTC]
Automatic comment on behalf of
Log: Fixed bug #79046
 [2019-12-30 16:24 UTC]
-Status: Verified +Status: Closed
PHP Copyright © 2001-2024 The PHP Group
All rights reserved.
Last updated: Thu Jul 25 11:01:30 2024 UTC