php gd protection against image decompression bomb

Viewed 385

Imagine a zip bomb, but in PNG flavour.

When doing any kind of image manipulation in gd it's almost inevitable that at some point the image is held entirely in memory in decompressed form via imagecreatefromjpeg and friends even for simple operations like resizing. getimagesize only extracts info from the metadata which can be unreliable.

What tools do we have to protect ourselves from such kinds of abuse, for example in the case of scaling down an image to create a thumbnail?

I thought about:

  • Making the server only accept uncompressed BMP or TIFF images and setting mere upload size limitations, with a client-side javascript that would convert jpg and png files to bmp before sending. Very bad for performance in general.
  • Actively reducing the available memory for the script in charge of doing the manipulation so that it would fail with an out-of-memory error if the image turns out to be too large (like 16 MB max memory). Bad on a whole new level of bad.

Do imagescale and similar functions need the original image to exist in memory decompressed?

Any other tips?

0 Answers
Related