Re: CFD: eXIF 2017-0207
John Bowler <[email protected]> Mon, 13 Feb 2017 09:47:30 -0800
| Newsgroups | gmane.comp.graphics.png.general |
|---|---|
| Message-ID | <CAP7U398LwbMmVz+BaBwaqJU12qhxD0K1vfgc0WoN1QFE1C2BGQ@mail.gmail.com> |
On Mon, Feb 13, 2017 at 5:52 AM, Phil Harvey <phil-CIeU6mJ2MbMd166Dz3SrqbDks+cytr/[email protected]> wrote: > By default, ExifTool doesn't copy the PreviewImage (like pngdumpmeta). Ok, Glenn also has a Nikon sample with a preview image, seems like it's mainly a Nikon "feature" but it means that data blocks which are outside the EXIF chunk exist in valid EXIF chunks and obviously they can exist in maliciously created ones. > However, pngdumpmeta is getting the wrong offset for the Olympus 0x0101 tag (SerialNumber) -- it has a perfectly good relative offset inside the makernote data area. A bug then, it's trying to decode the MakerNote tag data; MakerNote is a tag in the Exif directory which points to 9448 bytes of data and it's getting it wrong. That's a bug in the code, not a potential security issue in the Exif. I don't know if it is my code or exiv2; I might have messed something up. John Bowler ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot