diff options
author | Takeshi Abe <tabe@php.net> | 2010-01-14 11:11:56 +0000 |
---|---|---|
committer | Takeshi Abe <tabe@php.net> | 2010-01-14 11:11:56 +0000 |
commit | f7a3b3f5aa3f1eb4b8097513a0214b091c95504a (patch) | |
tree | b64ea18cf86966910e2dfec0559adf117bc216f6 /ext/gd | |
parent | fef4bf8a9d92b2371f1ed52ec31e449e763bc404 (diff) | |
download | php-git-f7a3b3f5aa3f1eb4b8097513a0214b091c95504a.tar.gz |
imagepolygon() and imagefilledpolygon() does not allow negative number of points causing invalid allocation
Diffstat (limited to 'ext/gd')
-rw-r--r-- | ext/gd/gd.c | 5 | ||||
-rw-r--r-- | ext/gd/libgd/gd.c | 4 | ||||
-rw-r--r-- | ext/gd/tests/imagefilledpolygon_negative.phpt | 15 | ||||
-rw-r--r-- | ext/gd/tests/imagepolygon_negative.phpt | 15 |
4 files changed, 36 insertions, 3 deletions
diff --git a/ext/gd/gd.c b/ext/gd/gd.c index 7eae7a52d2..238852286c 100644 --- a/ext/gd/gd.c +++ b/ext/gd/gd.c @@ -3427,7 +3427,10 @@ static void php_imagepolygon(INTERNAL_FUNCTION_PARAMETERS, int filled) php_error_docref(NULL TSRMLS_CC, E_WARNING, "You must have at least 3 points in your array"); RETURN_FALSE; } - + if (npoints <= 0) { + php_error_docref(NULL TSRMLS_CC, E_WARNING, "You must give a positive number of points"); + RETURN_FALSE; + } if (nelem < npoints * 2) { php_error_docref(NULL TSRMLS_CC, E_WARNING, "Trying to use %d points in array with only %d points", npoints, nelem/2); RETURN_FALSE; diff --git a/ext/gd/libgd/gd.c b/ext/gd/libgd/gd.c index a0ea6f198a..bbdfbe250b 100644 --- a/ext/gd/libgd/gd.c +++ b/ext/gd/libgd/gd.c @@ -2568,7 +2568,7 @@ void gdImagePolygon (gdImagePtr im, gdPointPtr p, int n, int c) typedef void (*image_line)(gdImagePtr im, int x1, int y1, int x2, int y2, int color); image_line draw_line; - if (!n) { + if (n <= 0) { return; } @@ -2621,7 +2621,7 @@ void gdImageFilledPolygon (gdImagePtr im, gdPointPtr p, int n, int c) int ints; int fill_color; - if (!n) { + if (n <= 0) { return; } diff --git a/ext/gd/tests/imagefilledpolygon_negative.phpt b/ext/gd/tests/imagefilledpolygon_negative.phpt new file mode 100644 index 0000000000..ced853067b --- /dev/null +++ b/ext/gd/tests/imagefilledpolygon_negative.phpt @@ -0,0 +1,15 @@ +--TEST-- +imagefilledpolygon() with a negative num of points +--SKIPIF-- +<?php + if (!function_exists('imagefilledpolygon')) die('skip imagefilledpolygon() not available'); +?> +--FILE-- +<?php +$im = imagecreate(100, 100); +$black = imagecolorallocate($im, 0, 0, 0); +if (imagefilledpolygon($im, array(0, 0, 0, 0, 0, 0), -1, $black)) echo "should be false"; +imagedestroy($im); +?> +--EXPECTF-- +Warning: imagefilledpolygon(): You must give a positive number of points in %s on line %d diff --git a/ext/gd/tests/imagepolygon_negative.phpt b/ext/gd/tests/imagepolygon_negative.phpt new file mode 100644 index 0000000000..bb9010c92f --- /dev/null +++ b/ext/gd/tests/imagepolygon_negative.phpt @@ -0,0 +1,15 @@ +--TEST-- +imagepolygon() with a negative num of points +--SKIPIF-- +<?php + if (!function_exists('imagepolygon')) die('skip imagepolygon() not available'); +?> +--FILE-- +<?php +$im = imagecreate(100, 100); +$black = imagecolorallocate($im, 0, 0, 0); +if (imagepolygon($im, array(0, 0, 0, 0, 0, 0), -1, $black)) echo "should be false"; +imagedestroy($im); +?> +--EXPECTF-- +Warning: imagepolygon(): You must give a positive number of points in %s on line %d |