Bug #55420 [Opn->Fbk]: Multiple TIFF SubIFDs are not handled correctly
| From: | kalle@php.net | Date: | Wed, 03 Aug 2016 03:55:22 +0000 |
| Subject: | Bug #55420 [Opn->Fbk]: Multiple TIFF SubIFDs are not handled correctly | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202853@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=55420&edit=1
ID: 55420
Updated by: kalle@php.net
Reported by: kde at timotheegroleau dot com
Summary: Multiple TIFF SubIFDs are not handled correctly
-Status: Open
+Status: Feedback
Type: Bug
Package: EXIF related
Operating System: gentoo linux amd64
PHP Version: 5.3.6
Block user comment: N
Private report: N
New Comment:
Hey!
I did a fix for bug #72735, which is committed to git in the master branch (PHP-7.2), could you
please test if that fix partially fixed some of this bug?
Previous Comments:
------------------------------------------------------------------------
[2011-08-14 16:38:11] kde at timotheegroleau dot com
Description:
------------
Tiff Tag SubIFD (330) ONLY works is there is a single SubIFD, but the Tiff
specifications state that SubIFDs is an array of IFDs of size tag_count.
If num_sub_ifd > 1, the tag long value is an offset to a sequence of longs,
themselves representing the offsets of each SubIFD.
In the source (ext/exif/exif.c) method exif_process_IFD_in_TIFF assumes that the
tag long value always points to ONE SubIFD (lines 3693 and 3698).
Effects:
1) If there is more than 1 SubIFD, the tiff parser will incorrectly be jumping
around in the file, potentially printing TONS of warnings
2) exif_thumbnail() does NOT work for Nikon nef files
Test script:
---------------
Download the 2 nef files (nikon nefs are tiff files) below:
http://nefarious.timotheegroleau.com/tests/dsc_2317.nef
http://nefarious.timotheegroleau.com/tests/out.nef
Run the following scripts from a php 5.3.6:
php -r 'var_dump(exif_read_data("dsc_2317.nef"));' 2>&1 |less
php -r 'var_dump(exif_read_data("out.nef"));' 2>&1 |less
Notice the single warning for dsc_2317.nef, as the parser is quickly encountering an invalid entry,
but notice also the ~39k warnings spat out for out.nef.
Note: I recommend enabling EXIF_DEBUG for this, to see the offsets printed (note btw that
there's a compilation error with EXIF_DEBUG on, which I've commented out for my tests)
Expected result:
----------------
exif data returned, with no warnings when the input tiff file has multiple
SubIFDs
Actual result:
--------------
exif data is returned, but based on the the input tiff, and where the SubIFD
offset sends the parser, there can be *A LOT* of warnings being thrown.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=55420&edit=1