8d87dc
Backported from 5.5.37 for 5.4 by Remi Collet
8d87dc
8d87dc
8d87dc
From c395c6e5d7e8df37a21265ff76e48fe75ceb5ae6 Mon Sep 17 00:00:00 2001
8d87dc
From: Stanislav Malyshev <stas@php.net>
8d87dc
Date: Mon, 20 Jun 2016 23:58:26 -0700
8d87dc
Subject: [PATCH] iFixed bug #72446 - Integer Overflow in
8d87dc
 gdImagePaletteToTrueColor() resulting in heap overflow
8d87dc
8d87dc
---
8d87dc
 NEWS              |  2 ++
8d87dc
 ext/gd/libgd/gd.c | 22 +++++++++++++---------
8d87dc
 2 files changed, 15 insertions(+), 9 deletions(-)
8d87dc
8d87dc
diff --git a/ext/gd/libgd/gd.c b/ext/gd/libgd/gd.c
8d87dc
index 2c63aac..4dad95a 100644
8d87dc
--- a/ext/gd/libgd/gd.c
8d87dc
+++ b/ext/gd/libgd/gd.c
8d87dc
@@ -133,6 +133,10 @@ gdImagePtr gdImageCreate (int sx, int sy)
8d87dc
 		return NULL;
8d87dc
 	}
8d87dc
 
8d87dc
+	if (overflow2(sizeof(unsigned char *), sx)) {
8d87dc
+		return NULL;
8d87dc
+	}
8d87dc
+
8d87dc
 	im = (gdImage *) gdCalloc(1, sizeof(gdImage));
8d87dc
 
8d87dc
 	/* Row-major ever since gd 1.3 */
8d87dc