Bug #18052 Updated: getimagesize() should not trust the header info in gifs

From: Date: Fri, 28 Jun 2002 20:23:00 +0000
Subject: Bug #18052 Updated: getimagesize() should not trust the header info in gifs
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-12451@lists.php.net to get a copy of this message
ID: 18052 Updated by: arpen@home.se Reported By: arpen@home.se Status: Open Bug Type: Feature/Change Request Operating System: Linux PHP Version: 4.2.1 New Comment: Oh, ok. My bad. I just figured it was a bug since getimagesize() can't determine the correct size. Previous Comments: ------------------------------------------------------------------------ [2002-06-28 16:12:57] derick@php.net Not a bug... making it a feature request ------------------------------------------------------------------------ [2002-06-28 16:09:39] arpen@home.se This is, as far as I know, "reproduceable" in all PHP versions and on on plattforms. ------------------------------------------------------------------------ [2002-06-28 15:27:23] arpen@home.se getimagesize() blindly trusts the width and height specified in the header of gifs. You can just hexedit the file and set the width and height to any value and getimagesize() will believe that is the "true size" of the image. Even worse - Internet Explorer ignores the width and height in the header and thus it is possible to, for instance, upload a much larger image in an upload form that uses getimagesize() than what is allowed. I believe getimagesize() should just skip the header and read the size from the beginning of the "Image Block". http://www.goice.co.jp/member/mo/formats/gif.html ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18052&edit=1

« previous php.bugs (#12451) next »