Bug #71848 [Ver]: getimagesize with $imageinfo returns false

From: Date: Fri, 22 Jun 2018 22:18:18 +0000
Subject: Bug #71848 [Ver]: getimagesize with $imageinfo returns false
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215876@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71848&edit=1 ID: 71848 Updated by: cmb@php.net Reported by: mail at mike-gladysch dot de Summary: getimagesize with $imageinfo returns false Status: Verified Type: Bug Package: GetImageSize related Operating System: irrelevant PHP Version: Irrelevant Block user comment: N Private report: N New Comment: <https://github.com/php/php-src/pull/3319> should solve this issue. Previous Comments: ------------------------------------------------------------------------ [2018-06-22 14:23:28] requinix@php.net Related To: Bug #76521 ------------------------------------------------------------------------ [2018-03-15 15:03:07] cmb@php.net Thanks for the images, freecorvette! It seems to me there are multiple not directly related issues. Firstly, php_read_APP()[1] fails for empty APP segments, but the first image contains an empty APP5 segment (starting at byte 430D). I am not sure whether empty APP segments are allowed according to the specification, but at least we could accept them. It is not clear, however, if we should add them to the $info with an empty string value, or simply omit them. Secondly, the check whether php_stream_read() succeeded[2] appears to be wrong. We should check whether it returned length – otherwise we're likely putting garbage from the buffer into the markers value a few lines below. Fixing this would also fix the first issue, adding the empty APP segment to $info with an empty string value. Thirdly, if php_handle_jpeg()[3] fails, it may nonetheless have already added entries to info, which might better be removed (perhaps we should even null info). [1] <https://github.com/php/php-src/blob/PHP-7.2.4/ext/standard/image.c#L441> [2] <https://github.com/php/php-src/blob/PHP-7.2.4/ext/standard/image.c#L456> [3] <https://github.com/php/php-src/blob/PHP-7.2.4/ext/standard/image.c#L475> ------------------------------------------------------------------------ [2017-10-03 07:48:58] freecorvette at gmail dot com The bug is still ocurring, in all PHP versions, so it should be reopened. Here is a simple test case (script posted, output posted, sample jpg images on Google Drive): Test file (test.php): <?php var_dump(getimagesize('17342761-mobileupload_d5f239209ef5cf6_3426572_20170617_103722.jpg')); var_dump(getimagesize('17342761-mobileupload_d5f239209ef5cf6_3426572_20170617_103722.jpg', $imageinfo)); var_dump($imageinfo); var_dump(getimagesize('17342761-mobileupload_d5f239209ef5cf6_2474645_20170617_110134.jpg')); var_dump(getimagesize('17342761-mobileupload_d5f239209ef5cf6_2474645_20170617_110134.jpg', $imageinfo)); var_dump($imageinfo); ?> Output: $ php test.php test.php:2: array(7) { [0] => int(4032) [1] => int(3024) [2] => int(2) [3] => string(26) "width="4032" height="3024"" 'bits' => int(8) 'channels' => int(3) 'mime' => string(10) "image/jpeg" } test.php:3: bool(false) test.php:4: array(1) { 'APP1' => \000\000\000\000\000\000�\000\000\000\000\000\000� \000\000\00\000\000\000�\000\000\000\000 \000\000\000�\000\000\000\000\000\000\000\000\000\000\000\000\000\000�\000\000\000\000\000\000\000�\000\000\000(\000\000\000\000\000\000\0001\000\000\000\000�\000\000\0002\000\000\000\000�\000\000\000\000\000\000\000\000\000\000i�\000\000\000\000�\000\000\000%�\000\000\000\000�\000\000�\000\000samsung\000SM-G935V\000\000H\000\000\000\"... } test.php:6: array(7) { [0] => int(4032) [1] => int(3024) [2] => int(2) [3] => string(26) "width="4032" height="3024"" 'bits' => int(8) 'channels' => int(3) 'mime' => string(10) "image/jpeg" } test.php:7: bool(false) test.php:8: array(1) { 'APP1' => \000\000\000\000\000\000�\000\000\000\000\000\000� \000\000\00\000\000\000�\000\000\000\000 \000\000\000�\000\000\000\000\000\000\000\000\000\000\000\000\000\000�\000\000\000\000\000\000\000�\000\000\000(\000\000\000\000\000\000\0001\000\000\000\000�\000\000\0002\000\000\000\000�\000\000\000\000\000\000\000\000\000\000i�\000\000\000\000�\000\000\000%�\000\000\000\000�\000\000�\000\000samsung\000SM-G935V\000\000H\000\000\000\"... } JPG images to test with: https://drive.google.com/file/d/0B9eJ8bp6Y-f0c3N2b0hycDBPaFU/view?usp=sharing https://drive.google.com/file/d/0B9eJ8bp6Y-f0WFhaTDBLSXdWTlk/view?usp=sharing One workaround is to use exif_read_data() in this case, i.e. the code would become: <?php var_dump(getimagesize('17342761-mobileupload_d5f239209ef5cf6_3426572_20170617_103722.jpg')); getimagesize('17342761-mobileupload_d5f239209ef5cf6_3426572_20170617_103722.jpg', $imageinfo); $exif = exif_read_data('17342761-mobileupload_d5f239209ef5cf6_3426572_20170617_103722.jpg', 'IFD0'); if ($exif !== false) { var_dump($exif); } else { var_dump(getimagesize('17342761-mobileupload_d5f239209ef5cf6_3426572_20170617_103722.jpg', $imageinfo)); var_dump($imageinfo); } var_dump(getimagesize('img130912-2.1.jpg')); $exif = exif_read_data('img130912-2.1.jpg', 'IFD0'); if ($exif !== false) { var_dump($exif); } else { var_dump(getimagesize('img130912-2.1.jpg', $imageinfo)); var_dump($imageinfo); } ?> but this is clearly a bug, either in PHP or in the underlying gd layer. ------------------------------------------------------------------------ [2016-08-07 04:22:24] php-bugs at lists dot php dot net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ [2016-07-30 19:52:13] kalle@php.net Can you provide a jpeg that can be used to replicate this bug? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71848 -- Edit this bug report at https://bugs.php.net/bug.php?id=71848&edit=1

« previous php.bugs (#215876) next »