Bug #67024 [Opn->Csd]: getimagesize should recognize BMP files with negative height

From: Date: Sun, 13 Apr 2014 22:27:03 +0000
Subject: Bug #67024 [Opn->Csd]: getimagesize should recognize BMP files with negative height
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-185223@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67024&edit=1 ID: 67024 Updated by: stas@php.net Reported by: gbuella at gmail dot com Summary: getimagesize should recognize BMP files with negative height -Status: Open +Status: Closed Type: Bug Package: GetImageSize related PHP Version: master-Git-2014-04-04 (Git) Block user comment: N Private report: N New Comment: Automatic comment on behalf of gbuella@gmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=1010200da5da81642bec89d9c90d001478e3554d Log: Fixed bug #67024 - getimagesize should recognize BMP files with negative height Previous Comments: ------------------------------------------------------------------------ [2014-04-04 22:14:54] gbuella at gmail dot com Description: ------------ The functions getimagesize, and getimagesizefromstring treat the height field of a BITMAPINFOHEADER header as an unsigned integer, while it really is a signed integer. On platforms with 64 bit PHP integers, this results in height being reported as 4294966272 for an image with height -1024, instead of the expected result height=1024. Test script: --------------- <?php $image_data = "Qk06AAAAAAAAADYAAAAoAAAAAQAAAP////8BABgAAAAAAAQAAADDDgAAww4AAAAAAAAAAAAA////AA=="; var_dump(getimagesizefromstring(base64_decode($image_data))); ?> Expected result: ---------------- array(6) { [0]=> int(1) [1]=> int(1) [2]=> int(6) [3]=> string(20) "width="1" height="1"" ["bits"]=> int(24) ["mime"]=> string(14) "image/x-ms-bmp" } Actual result: -------------- array(6) { [0]=> int(1) [1]=> int(4294967295) [2]=> int(6) [3]=> string(21) "width="1" height="-1"" ["bits"]=> int(24) ["mime"]=> string(14) "image/x-ms-bmp" } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67024&edit=1

« previous php.bugs (#185223) next »