Bug #74239 [Opn->Ver]: getimagesize returns incorrect value for corrupt file.
| From: | cmb@php.net | Date: | Fri, 17 Mar 2017 11:59:01 +0000 |
| Subject: | Bug #74239 [Opn->Ver]: getimagesize returns incorrect value for corrupt file. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207890@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74239&edit=1
ID: 74239
Updated by: cmb@php.net
Reported by: akaamitgupta at gmail dot com
Summary: getimagesize returns incorrect value for corrupt
file.
-Status: Open
+Status: Verified
Type: Bug
-Package: *General Issues
+Package: GetImageSize related
Operating System: Mac OSX
PHP Version: 5.6.30
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
From the manual[1]:
| This function expects filename to be a valid image file. If a
| non-image file is supplied, it may be incorrectly detected as an
| image and the function will return successfully.
This notice should better be moved to a more prominent place, and be
improved. So I'm changing to doc-bug.
[1] <http://php.net/manual/en/function.getimagesize.php#refsect1-function.getimagesize-notes>
Previous Comments:
------------------------------------------------------------------------
[2017-03-12 10:12:03] akaamitgupta at gmail dot com
Description:
------------
I have wrapped an executable inside an image which has the following content -
GIF89a<?php
echo 'hacked';
?>
and saved it as filename image.gif.
Whene I use getimagesize() PHP function then it returns
array:6 [â¼
0 => 16188
1 => 26736
2 => 1
3 => "width="16188" height="26736""
"channels" => 3
"mime" => "image/gif"
]
although image is not valid but still it has valid width and height.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74239&edit=1