Re: CFD: eXIF 2017-0207
John Bowler <[email protected]> Fri, 10 Feb 2017 09:00:18 -0800
| Newsgroups | gmane.comp.graphics.png.general |
|---|---|
| Message-ID | <CAP7U3998axLaOB6iJNspyKwz8WZG4xzc76jJUvb4BJmya3sbtA@mail.gmail.com> |
On Fri, Feb 10, 2017 at 6:09 AM, Phil Harvey <phil-CIeU6mJ2MbMd166Dz3SrqbDks+cytr/[email protected]> wrote: > Just FYI in case anyone wants to play with eXIF/zXIF, the latest version of ExifTool supports reading and writing both eXIF and zXIF (add the -z option when writing to create the compressed zXIF): I've noticed that one of the JPEG samples (one of mine IRC) has an EXIF tag which exiv2 reports as containing offsets outside the chunk. I suspect this may be related to the other unusual practice of storing a "preview" image after the EOI of the main (IFD[0]) image. Are you aware of this? (Obviously it can happen in a maliciously generated EXIF or TIFF, but it seems to be happening deliberately without real malicious intent.) It seems it must be a consistent security issue in EXIF (indeed, in TIFF in general) because a careless decoder might fail to check the offsets. John Bowler ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot