Re: CFD: eXIF 2017-0207
John Bowler <[email protected]> Sun, 12 Feb 2017 20:01:18 -0800
| Newsgroups | gmane.comp.graphics.png.general |
|---|---|
| Message-ID | <CAP7U39_JXxRyVACz3JPFpRX2DLKi9yb7qCXVNTgXEx8srV8ijA@mail.gmail.com> |
On Sun, Feb 12, 2017 at 7:46 PM, Glenn Randers-Pehrson <[email protected]> wrote: > Tomorrow I'll update the eXIf proposal with this: > > 135c135,139 > < This chunk does not introduce additional security issues. > --- >> The Exif specification does not contain a requirement that >> tag "value offset" pointers actually point to a valid address >> within the file (see Paragraph 4.6.2). Although this seems to be >> an implicit requrement, decoders should be prepared to encounter invalid >> pointers and deal with them appropriately. Indeed, iCCP has the same issue. FWIW, PNG does not have that issue; I believe it is inherently secure in that regard. The issue only arises with tags which have their own structure and, at this point, I think that is only iCCP. John Bowler ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot