|
|
b77848 |
From cf4753691dc55999373d1c576f62ecb298723420 Mon Sep 17 00:00:00 2001
|
|
|
b77848 |
From: Remi Collet <remi@php.net>
|
|
|
b77848 |
Date: Mon, 4 Aug 2014 10:42:39 +0200
|
|
|
b77848 |
Subject: [PATCH] Fixed Bug #66901 php-gd 'c_color' NULL pointer dereference
|
|
|
b77848 |
|
|
|
b77848 |
Upstream https://bitbucket.org/libgd/gd-libgd/commits/463c3bd09bfe8e924e19acad7a2a6af16953a704
|
|
|
b77848 |
|
|
|
b77848 |
Notice: this fix don't manage monochrome/monovisual values
|
|
|
b77848 |
but just fix the security issue CVE-2014-2497
|
|
|
b77848 |
failing when trying to load such an image
|
|
|
b77848 |
---
|
|
|
b77848 |
ext/gd/libgd/gdxpm.c | 7 ++++++-
|
|
|
b77848 |
1 file changed, 6 insertions(+), 1 deletion(-)
|
|
|
b77848 |
|
|
|
b77848 |
diff --git a/ext/gd/libgd/gdxpm.c b/ext/gd/libgd/gdxpm.c
|
|
|
b77848 |
index 73f86e5..b69414e 100644
|
|
|
b77848 |
--- a/ext/gd/libgd/gdxpm.c
|
|
|
b77848 |
+++ b/ext/gd/libgd/gdxpm.c
|
|
|
b77848 |
@@ -31,12 +31,17 @@ gdImagePtr gdImageCreateFromXpm (char *filename)
|
|
|
b77848 |
if (ret != XpmSuccess) {
|
|
|
b77848 |
return 0;
|
|
|
b77848 |
}
|
|
|
b77848 |
+ number = image.ncolors;
|
|
|
b77848 |
+ for(i = 0; i < number; i++) {
|
|
|
b77848 |
+ if (!image.colorTable[i].c_color) {
|
|
|
b77848 |
+ goto done;
|
|
|
b77848 |
+ }
|
|
|
b77848 |
+ }
|
|
|
b77848 |
|
|
|
b77848 |
if (!(im = gdImageCreate(image.width, image.height))) {
|
|
|
b77848 |
goto done;
|
|
|
b77848 |
}
|
|
|
b77848 |
|
|
|
b77848 |
- number = image.ncolors;
|
|
|
b77848 |
colors = (int *) safe_emalloc(number, sizeof(int), 0);
|
|
|
b77848 |
for (i = 0; i < number; i++) {
|
|
|
b77848 |
switch (strlen (image.colorTable[i].c_color)) {
|
|
|
b77848 |
--
|
|
|
b77848 |
1.9.2
|
|
|
b77848 |
|