Re: CFD: eXIF 2017-0207

John Bowler <[email protected]> Sun, 12 Feb 2017 18:59:59 -0800
Newsgroups gmane.comp.graphics.png.general
Message-ID <CAP7U398SxOJZA6TRT2M1Md0Koz73c_Q2oYQd06Xnq4sAv56QzQ@mail.gmail.com>
On Sun, Feb 12, 2017 at 6:16 PM, Glenn Randers-Pehrson
<[email protected]> wrote:
> This seems to be worth mentioning in the Security Considerations,
> namely that decoders should be prepared to encounter tag offsets
> that reference data outside the chunk data segment.

Yes, I believe it is, but not because of, rather despite, what Phil
said; it's a known issue, something that decoders need to be aware of
for sure, but still known.  It's also fairly obvious; it's a TIFF
issue and any cracker worth his salt is going to know how to make it.

Simply because digital cameras produce this error it is less serious,
which is somewhat ironic.

So far it is the only thing that I think is really well worth mention
as a Security Consideration; while it duplicates what everyone else
who decodes TIFF must realize it is sufficiently serious to mention
every time.  (Yes; anyone who decodes a file format is aware, has bred
into their soul, that an offset is a pointer you got from someone you
cannot trust, but all the same.)

-- 
John Bowler <[email protected]>
+1 (541) 450-9885
PO BOX 3151
KERBY OR 97531-3151
USA

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, SlashDot.org! http://sdm.link/slashdot