Bug #15174 Updated: JPEG SOFn marker incompletely read

From: Date: Sat, 09 Mar 2002 16:00:59 +0000
Subject: Bug #15174 Updated: JPEG SOFn marker incompletely read
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-2099@lists.php.net to get a copy of this message
ID: 15174 Updated by: helly@php.net Reported By: mul@rentapacs.com -Status: Open +Status: Closed Bug Type: GetImageSize related Operating System: Linux PHP Version: 4.1.1 -Assigned To: +Assigned To: helly New Comment: SOFn sections have format: LL B HH WW C C*3 L=length of section B=bits per sample H=height w=width c=channels +3*c bytes for channel information code will be added in next cvs version / php 4.3 Previous Comments: ------------------------------------------------------------------------ [2002-01-22 15:54:25] mul@rentapacs.com In ext/standard/image.c:static struct gfxinfo *php_handle_jpeg(): After $result->channels has been read from the file, there are still $result->channels * 3 bytes left in the SOF marker. These bytes have to be read to synchronize reading of the following markers in the JPEG stream. If not, bogus markers will be decoded and SOS marker will be missed in most cases. The following patch against 4.1.1 might take care of the problem: --- ext/standard/image.c.orig Sat Aug 11 19:03:37 2001 +++ ext/standard/image.c Tue Jan 22 21:14:31 2002 @@ -323,6 +323,8 @@ unsigned int marker; char tmp[2]; unsigned char a[4]; + unsigned short skip; + unsigned char *buffer; for (;;) { marker = php_next_marker(socketd, fp, issock); @@ -349,6 +351,11 @@ result->height = (((unsigned short) a[ 0 ]) << 8) + ((unsigned short) a[ 1 ]); result->width = (((unsigned short) a[ 2 ]) << 8) + ((unsigned short) a[ 3 ]); result->channels = FP_FGETC(socketd, fp, issock); + /* skip component specification parameters */ + skip = result->channels * 3; + buffer = emalloc(skip); + FP_FREAD(buffer, (long) skip, socketd, fp, issock); + efree(buffer); if (! info) /* if we don't want an extanded info -> return */ return result; ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=15174&edit=1

« previous php.bugs (#2099) next »