summaryrefslogtreecommitdiff
path: root/ext/gd
diff options
context:
space:
mode:
authorTakeshi Abe <tabe@php.net>2010-01-14 11:11:56 +0000
committerTakeshi Abe <tabe@php.net>2010-01-14 11:11:56 +0000
commitf7a3b3f5aa3f1eb4b8097513a0214b091c95504a (patch)
treeb64ea18cf86966910e2dfec0559adf117bc216f6 /ext/gd
parentfef4bf8a9d92b2371f1ed52ec31e449e763bc404 (diff)
downloadphp-git-f7a3b3f5aa3f1eb4b8097513a0214b091c95504a.tar.gz
imagepolygon() and imagefilledpolygon() does not allow negative number of points causing invalid allocation
Diffstat (limited to 'ext/gd')
-rw-r--r--ext/gd/gd.c5
-rw-r--r--ext/gd/libgd/gd.c4
-rw-r--r--ext/gd/tests/imagefilledpolygon_negative.phpt15
-rw-r--r--ext/gd/tests/imagepolygon_negative.phpt15
4 files changed, 36 insertions, 3 deletions
diff --git a/ext/gd/gd.c b/ext/gd/gd.c
index 7eae7a52d2..238852286c 100644
--- a/ext/gd/gd.c
+++ b/ext/gd/gd.c
@@ -3427,7 +3427,10 @@ static void php_imagepolygon(INTERNAL_FUNCTION_PARAMETERS, int filled)
php_error_docref(NULL TSRMLS_CC, E_WARNING, "You must have at least 3 points in your array");
RETURN_FALSE;
}
-
+ if (npoints <= 0) {
+ php_error_docref(NULL TSRMLS_CC, E_WARNING, "You must give a positive number of points");
+ RETURN_FALSE;
+ }
if (nelem < npoints * 2) {
php_error_docref(NULL TSRMLS_CC, E_WARNING, "Trying to use %d points in array with only %d points", npoints, nelem/2);
RETURN_FALSE;
diff --git a/ext/gd/libgd/gd.c b/ext/gd/libgd/gd.c
index a0ea6f198a..bbdfbe250b 100644
--- a/ext/gd/libgd/gd.c
+++ b/ext/gd/libgd/gd.c
@@ -2568,7 +2568,7 @@ void gdImagePolygon (gdImagePtr im, gdPointPtr p, int n, int c)
typedef void (*image_line)(gdImagePtr im, int x1, int y1, int x2, int y2, int color);
image_line draw_line;
- if (!n) {
+ if (n <= 0) {
return;
}
@@ -2621,7 +2621,7 @@ void gdImageFilledPolygon (gdImagePtr im, gdPointPtr p, int n, int c)
int ints;
int fill_color;
- if (!n) {
+ if (n <= 0) {
return;
}
diff --git a/ext/gd/tests/imagefilledpolygon_negative.phpt b/ext/gd/tests/imagefilledpolygon_negative.phpt
new file mode 100644
index 0000000000..ced853067b
--- /dev/null
+++ b/ext/gd/tests/imagefilledpolygon_negative.phpt
@@ -0,0 +1,15 @@
+--TEST--
+imagefilledpolygon() with a negative num of points
+--SKIPIF--
+<?php
+ if (!function_exists('imagefilledpolygon')) die('skip imagefilledpolygon() not available');
+?>
+--FILE--
+<?php
+$im = imagecreate(100, 100);
+$black = imagecolorallocate($im, 0, 0, 0);
+if (imagefilledpolygon($im, array(0, 0, 0, 0, 0, 0), -1, $black)) echo "should be false";
+imagedestroy($im);
+?>
+--EXPECTF--
+Warning: imagefilledpolygon(): You must give a positive number of points in %s on line %d
diff --git a/ext/gd/tests/imagepolygon_negative.phpt b/ext/gd/tests/imagepolygon_negative.phpt
new file mode 100644
index 0000000000..bb9010c92f
--- /dev/null
+++ b/ext/gd/tests/imagepolygon_negative.phpt
@@ -0,0 +1,15 @@
+--TEST--
+imagepolygon() with a negative num of points
+--SKIPIF--
+<?php
+ if (!function_exists('imagepolygon')) die('skip imagepolygon() not available');
+?>
+--FILE--
+<?php
+$im = imagecreate(100, 100);
+$black = imagecolorallocate($im, 0, 0, 0);
+if (imagepolygon($im, array(0, 0, 0, 0, 0, 0), -1, $black)) echo "should be false";
+imagedestroy($im);
+?>
+--EXPECTF--
+Warning: imagepolygon(): You must give a positive number of points in %s on line %d