Re: DRAFT: eXIf 2017-03-09

John Bowler <[email protected]> Thu, 9 Mar 2017 19:52:55 -0800
Newsgroups gmane.comp.graphics.png.general
Message-ID <CAP7U39_sS1rxMehnjkMsC9YpiVC013oRDEC7jN4seOGXvvdeYQ@mail.gmail.com>
[Therefore, it begins with a standard TIFF header (starting with
either "II" or "MM", depending upon the byte order used), and contains
a 0th IFD (Image File Directory) and optionally a 1st IFD. The 0th IFD
may contain pointers to an Exif IFD and/or a GPS IFD, and the 1st IFD
(if any) contains a thumbnail image. Any gap preceding an IFD is
filled with bytes of unspecified content.]

This seems unhelpful.   It begs the (security) question of whether the
gap can be detected; so far as I can see tags in the IFDs can point
anywhere and, so far as I can see, unrecognized tags which might point
anywhere (perhaps indirectly) are permitted.

I think this is raising a whole collection of TIFF security issues
which should not be part of a PNG specification.

John Bowler

------------------------------------------------------------------------------
Announcing the Oxford Dictionaries API! The API offers world-renowned
dictionary content that is easy and intuitive to access. Sign up for an
account today to start using our lexical data to power your apps and
projects. Get started today and enter our developer competition.
http://sdm.link/oxford