Re: CFD: eXIF 2017-0207
John Bowler <[email protected]> Sun, 12 Feb 2017 18:59:59 -0800
| Newsgroups | gmane.comp.graphics.png.general |
|---|---|
| Message-ID | <CAP7U398SxOJZA6TRT2M1Md0Koz73c_Q2oYQd06Xnq4sAv56QzQ@mail.gmail.com> |
On Sun, Feb 12, 2017 at 6:16 PM, Glenn Randers-Pehrson <[email protected]> wrote: > This seems to be worth mentioning in the Security Considerations, > namely that decoders should be prepared to encounter tag offsets > that reference data outside the chunk data segment. Yes, I believe it is, but not because of, rather despite, what Phil said; it's a known issue, something that decoders need to be aware of for sure, but still known. It's also fairly obvious; it's a TIFF issue and any cracker worth his salt is going to know how to make it. Simply because digital cameras produce this error it is less serious, which is somewhat ironic. So far it is the only thing that I think is really well worth mention as a Security Consideration; while it duplicates what everyone else who decodes TIFF must realize it is sufficiently serious to mention every time. (Yes; anyone who decodes a file format is aware, has bred into their soul, that an offset is a pointer you got from someone you cannot trust, but all the same.) -- John Bowler <[email protected]> +1 (541) 450-9885 PO BOX 3151 KERBY OR 97531-3151 USA ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot