Re: CFD: eXIF 2017-0207

John Bowler <[email protected]> Fri, 10 Feb 2017 09:00:18 -0800
Newsgroups gmane.comp.graphics.png.general
Message-ID <CAP7U3998axLaOB6iJNspyKwz8WZG4xzc76jJUvb4BJmya3sbtA@mail.gmail.com>
On Fri, Feb 10, 2017 at 6:09 AM, Phil Harvey <phil-CIeU6mJ2MbMd166Dz3SrqbDks+cytr/[email protected]> wrote:
> Just FYI in case anyone wants to play with eXIF/zXIF, the latest version of ExifTool supports reading and writing both eXIF and zXIF (add the -z option when writing to create the compressed zXIF):

I've noticed that one of the JPEG samples (one of mine IRC) has an
EXIF tag which exiv2 reports as containing offsets outside the chunk.
I suspect this may be related to the other unusual practice of storing
a "preview" image after the EOI of the main (IFD[0]) image.  Are you
aware of this?  (Obviously it can happen in a maliciously generated
EXIF or TIFF, but it seems to be happening deliberately without real
malicious intent.)

It seems it must be a consistent security issue in EXIF (indeed, in
TIFF in general) because a careless decoder might fail to check the
offsets.

John Bowler

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, SlashDot.org! http://sdm.link/slashdot