Bug #18052 Updated: getimagesize() should not trust the header info in gifs
| From: | derick@php.net | Date: | Fri, 28 Jun 2002 20:12:57 +0000 |
| Subject: | Bug #18052 Updated: getimagesize() should not trust the header info in gifs | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-12449@lists.php.net to get a copy of this message | ||
ID: 18052
Updated by: derick@php.net
Reported By: arpen@home.se
Status: Open
-Bug Type: GetImageSize related
+Bug Type: Feature/Change Request
Operating System: Linux
PHP Version: 4.2.1
New Comment:
Not a bug... making it a feature request
Previous Comments:
------------------------------------------------------------------------
[2002-06-28 16:09:39] arpen@home.se
This is, as far as I know, "reproduceable" in all PHP versions and on
on plattforms.
------------------------------------------------------------------------
[2002-06-28 15:27:23] arpen@home.se
getimagesize() blindly trusts the width and height specified in the
header of gifs. You can just hexedit the file and set the width and
height to any value and getimagesize() will believe that is the "true
size" of the image. Even worse - Internet Explorer ignores the width
and height in the header and thus it is possible to, for instance,
upload a much larger image in an upload form that uses getimagesize()
than what is allowed. I believe getimagesize() should just skip the
header and read the size from the beginning of the "Image Block".
http://www.goice.co.jp/member/mo/formats/gif.html
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=18052&edit=1