Skip to content

Test files for CVEs #5392

Description

@frenzymadness

Hello.

Would it be possible to add tests and test files for:

Files for verification of the fixes are more than enough, I'd happily contribute tests with them.

Thanks for considering this.

Activity

  1. wiredfool commented on Apr 8, 2021

    @wiredfool
    Member

    There was a test for the RegexDOS, but I'm not seeing it now.

    The other ones -- there was an ICO file that showed the issue, and the other locations with the same code pattern were fixed up without a test case.

  2. frenzymadness commented on Apr 8, 2021

    @frenzymadness
    ContributorAuthor

    To be completely honest, I'm backporting the fixes to an older version of Pillow and I'd like to have something to test it with.

    But in general, it's a good idea to have the files in tests to avoid regressions, especially for security issues.

    Do you know where I can find the mentioned files?

  3. hugovk commented on Apr 8, 2021

    @hugovk
    Member

    For the ReDoS fix I used this to test it, but didn't work it into a test case:

    from PIL.PdfParser import PdfParser
    malicious = b' trailer<<>>' + b'\n' * 3456
    PdfParser(buf=malicious)

    With pre-fix master - 30.958 seconds:

    $ time python redos.py
    Traceback (most recent call last):
      File "/Users/hugo/github/Pillow/redos.py", line 3, in <module>
        PdfParser(buf=malicious)
      File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 376, in __init__
        self.read_pdf_info()
      File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 542, in read_pdf_info
        self.read_trailer()
      File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 620, in read_trailer
        check_format_condition(m, "trailer end not found")
      File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 78, in check_format_condition
        raise PdfFormatError(error_message)
    PIL.PdfParser.PdfFormatError: trailer end not found
    python3 redos.py  29.87s user 0.26s system 97% cpu 30.958 total

    With PR - 0.225 seconds:

    $ time python redos.py
    Traceback (most recent call last):
      File "/Users/hugo/github/Pillow/redos.py", line 3, in <module>
        PdfParser(buf=malicious)
      File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 376, in __init__
        self.read_pdf_info()
      File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 542, in read_pdf_info
        self.read_trailer()
      File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 621, in read_trailer
        check_format_condition(m, "trailer end not found")
      File "/Users/hugo/github/Pillow/src/PIL/PdfParser.py", line 78, in check_format_condition
        raise PdfFormatError(error_message)
    PIL.PdfParser.PdfFormatError: trailer end not found
    python3 redos.py  0.13s user 0.07s system 88% cpu 0.225 total
  4. wiredfool commented on Apr 8, 2021

    @wiredfool
    Member

    That could pretty easily be put in with the pytest-timeout now.

    As for the other ones, there are no test cases because they're a theoretical vulnerability. I found the ICNS with oss-fuzz, and looked for all other cases of that class of error and fixed them. It didn't seem to be a great use of my time to go in with a hex editor and make up specific malicious j2k, ico, or blp images. We did similar things with the malloc checks -- we'll go through and attempt to eliminate all cases of a class of bug, even if we don't have anything that will exercise it.

  5. hugovk commented on Apr 8, 2021

    @hugovk
    Member

    Good idea, please see PR #5393 for a ReDoS unit test.

  6. frenzymadness commented on Apr 9, 2021

    @frenzymadness
    ContributorAuthor

    Thanks a lot!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions