Re: DRAFT: eXIf 2017-03-09

John Bowler <[email protected]> Sat, 11 Mar 2017 19:03:50 -0800
Newsgroups gmane.comp.graphics.png.general
Message-ID <CAP7U39-1tc1D1BAA2QmB89N89Fq73utoOfbM5ed92ebnSXHO5w@mail.gmail.com>
EXIF/ITFF and ICC seem to have this problem in common; they both
contain a table (ICC) or tables (TIFF) which contain offsets to data
outside the tables.  It is pretty easy to deliberately produce valid
ICC profiles which contain bytes that are not referenced by any entry
in the table and, so far as I can see, the same applies to EXIF.

However this seems to me to be a trivial security issue.  For sure an
encoder might leave a gap, but for it to be a security issue the
encoder has to leave the gap filled within interesting data.  Yes, I
know this happens, but this is two bad bugs; what does warning encoder
writers that they could write a valid EXIF chunk with uninitialized
data actually achieve?

John Bowler

------------------------------------------------------------------------------
Announcing the Oxford Dictionaries API! The API offers world-renowned
dictionary content that is easy and intuitive to access. Sign up for an
account today to start using our lexical data to power your apps and
projects. Get started today and enter our developer competition.
http://sdm.link/oxford