Bug #55420 [Opn->Fbk]: Multiple TIFF SubIFDs are not handled correctly

From: Date: Wed, 03 Aug 2016 03:55:22 +0000
Subject: Bug #55420 [Opn->Fbk]: Multiple TIFF SubIFDs are not handled correctly
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202853@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=55420&edit=1 ID: 55420 Updated by: kalle@php.net Reported by: kde at timotheegroleau dot com Summary: Multiple TIFF SubIFDs are not handled correctly -Status: Open +Status: Feedback Type: Bug Package: EXIF related Operating System: gentoo linux amd64 PHP Version: 5.3.6 Block user comment: N Private report: N New Comment: Hey! I did a fix for bug #72735, which is committed to git in the master branch (PHP-7.2), could you please test if that fix partially fixed some of this bug? Previous Comments: ------------------------------------------------------------------------ [2011-08-14 16:38:11] kde at timotheegroleau dot com Description: ------------ Tiff Tag SubIFD (330) ONLY works is there is a single SubIFD, but the Tiff specifications state that SubIFDs is an array of IFDs of size tag_count. If num_sub_ifd > 1, the tag long value is an offset to a sequence of longs, themselves representing the offsets of each SubIFD. In the source (ext/exif/exif.c) method exif_process_IFD_in_TIFF assumes that the tag long value always points to ONE SubIFD (lines 3693 and 3698). Effects: 1) If there is more than 1 SubIFD, the tiff parser will incorrectly be jumping around in the file, potentially printing TONS of warnings 2) exif_thumbnail() does NOT work for Nikon nef files Test script: --------------- Download the 2 nef files (nikon nefs are tiff files) below: http://nefarious.timotheegroleau.com/tests/dsc_2317.nef http://nefarious.timotheegroleau.com/tests/out.nef Run the following scripts from a php 5.3.6: php -r 'var_dump(exif_read_data("dsc_2317.nef"));' 2>&1 |less php -r 'var_dump(exif_read_data("out.nef"));' 2>&1 |less Notice the single warning for dsc_2317.nef, as the parser is quickly encountering an invalid entry, but notice also the ~39k warnings spat out for out.nef. Note: I recommend enabling EXIF_DEBUG for this, to see the offsets printed (note btw that there's a compilation error with EXIF_DEBUG on, which I've commented out for my tests) Expected result: ---------------- exif data returned, with no warnings when the input tiff file has multiple SubIFDs Actual result: -------------- exif data is returned, but based on the the input tiff, and where the SubIFD offset sends the parser, there can be *A LOT* of warnings being thrown. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=55420&edit=1

« previous php.bugs (#202853) next »