Skip to content

Commit 2d05da2

Browse files
committed
Fix GH-16260: overflow/underflow on imagerotate degrees argument.
close GH-16264
1 parent 6d9903f commit 2d05da2

File tree

3 files changed

+30
-1
lines changed

3 files changed

+30
-1
lines changed

NEWS

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,8 +34,10 @@ PHP NEWS
3434
(nielsdos)
3535

3636
- GD:
37-
. Fixed bug 16232 (bitshift overflow on wbmp file content reading /
37+
. Fixed bug GH-16232 (bitshift overflow on wbmp file content reading /
3838
fix backport from upstream). (David Carlier)
39+
. Fixed bug GH-12264 (overflow/underflow on imagerotate degrees value)
40+
(David Carlier)
3941

4042
- LDAP:
4143
. Fixed bug GH-16032 (Various NULL pointer dereferencements in

ext/gd/gd.c

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1195,6 +1195,11 @@ PHP_FUNCTION(imagerotate)
11951195
RETURN_THROWS();
11961196
}
11971197

1198+
if (degrees < (double)(INT_MIN / 100) || degrees > (double)(INT_MAX / 100)) {
1199+
zend_argument_value_error(2, "must be between %d and %d", (INT_MIN / 100), (INT_MAX / 100));
1200+
RETURN_THROWS();
1201+
}
1202+
11981203
im_src = php_gd_libgdimageptr_from_zval_p(SIM);
11991204
im_dst = gdImageRotateInterpolated(im_src, (const float)degrees, color);
12001205

ext/gd/tests/gh16260.phpt

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
--TEST--
2+
GH-16260 (Overflow/underflow on imagerotate degrees argument)
3+
--EXTENSIONS--
4+
gd
5+
--FILE--
6+
<?php
7+
$im = imagecreatetruecolor(10,10);
8+
9+
try {
10+
imagerotate($im, PHP_INT_MIN, 0);
11+
} catch (\ValueError $e) {
12+
echo $e->getMessage() . PHP_EOL;
13+
}
14+
15+
try {
16+
imagerotate($im, PHP_INT_MAX, 0);
17+
} catch (\ValueError $e) {
18+
echo $e->getMessage();
19+
}
20+
--EXPECTF--
21+
imagerotate(): Argument #2 ($angle) must be between %s and %s
22+
imagerotate(): Argument #2 ($angle) must be between %s and %s

0 commit comments

Comments
 (0)