Repository navigation
Test files for CVEs #5392
Description
Activity
There was a test for the RegexDOS, but I'm not seeing it now.
The other ones -- there was an ICO file that showed the issue, and the other locations with the same code pattern were fixed up without a test case.
To be completely honest, I'm backporting the fixes to an older version of Pillow and I'd like to have something to test it with.
But in general, it's a good idea to have the files in tests to avoid regressions, especially for security issues.
Do you know where I can find the mentioned files?
For the ReDoS fix I used this to test it, but didn't work it into a test case:
from PIL.PdfParser import PdfParser malicious = b' trailer<<>>' + b'\n' * 3456 PdfParser(buf=malicious)
With pre-fix
master- 30.958 seconds:$ time python redos.py Traceback (most recent call last): File "/Users/hugo/github/Pillow/redos.py", line 3, in <module> PdfParser(buf=malicious) File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 376, in __init__ self.read_pdf_info() File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 542, in read_pdf_info self.read_trailer() File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 620, in read_trailer check_format_condition(m, "trailer end not found") File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 78, in check_format_condition raise PdfFormatError(error_message) PIL.PdfParser.PdfFormatError: trailer end not found python3 redos.py 29.87s user 0.26s system 97% cpu 30.958 total
With PR - 0.225 seconds:
$ time python redos.py Traceback (most recent call last): File "/Users/hugo/github/Pillow/redos.py", line 3, in <module> PdfParser(buf=malicious) File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 376, in __init__ self.read_pdf_info() File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 542, in read_pdf_info self.read_trailer() File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 621, in read_trailer check_format_condition(m, "trailer end not found") File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 78, in check_format_condition raise PdfFormatError(error_message) PIL.PdfParser.PdfFormatError: trailer end not found python3 redos.py 0.13s user 0.07s system 88% cpu 0.225 total
That could pretty easily be put in with the pytest-timeout now.
As for the other ones, there are no test cases because they're a theoretical vulnerability. I found the ICNS with oss-fuzz, and looked for all other cases of that class of error and fixed them. It didn't seem to be a great use of my time to go in with a hex editor and make up specific malicious j2k, ico, or blp images. We did similar things with the malloc checks -- we'll go through and attempt to eliminate all cases of a class of bug, even if we don't have anything that will exercise it.
Good idea, please see PR #5393 for a ReDoS unit test.
Thanks a lot!
Reacted by Hugo van Kemenade
Hello.
Would it be possible to add tests and test files for:
Files for verification of the fixes are more than enough, I'd happily contribute tests with them.
Thanks for considering this.