Bug #79045 [NEW]: incorrect svg mimetypes

From: Date: Mon, 30 Dec 2019 01:30:14 +0000
Subject: Bug #79045 [NEW]: incorrect svg mimetypes
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-224604@lists.php.net to get a copy of this message
From:             sloth at 0k dot vc
Operating system: Centos 7.5
PHP version:      7.2.26
Package:          Filesystem function related
Bug Type:         Bug
Bug description:incorrect svg mimetypes

Description:
------------
PHP when given an svg perhaps without the xml header, will return a mime
type of image/svg instead of image/svg+xml, however IANA does not list
image/svg as an existant mimetype, nor do browsers display it.
(https://www.iana.org/assignments/media-types/media-types.xhtml)

By SVG standards, mimetype returned should always be image/svg+xml, php
should also behave consistently for a single type of file. If this is
being used to differentiate properly headered SVGs from those that are
not as strict, this should be done as part of a file validity check not
a mime type check.

Previously reported bug (https://bugs.php.net/bug.php?id=76543) was
indicated as "Not a bug" due to it being deemed as upstream fault with
libmagic. However, libmagic returns svgs missing the xml header as
text/plain. This indicates the fault is in the adaptations PHP took to
remove that error.

└(~) $ file -i Test.svg
Test.svg: image/svg+xml; charset=utf-8
└(~) $ file -i badge.svg
badge.svg: text/plain; charset=us-ascii

As only php is returning image/svg and this is not a registered
mimetype, this can be considered a bug with php.

Test images:
Working svg+xml:
https://upload.wikimedia.org/wikipedia/commons/b/bd/Test.svg
SVG returned as image/svg:
https://img.shields.io/badge/License-WTFPL-brightgreen.svg

Test script:
---------------
<?php
echo mime_content_type('./badge.svg'), "\n";
echo mime_content_type('./Test.svg'), "\n";

$finfo = new finfo(FILEINFO_MIME);

$buffer = file_get_contents('./badge.svg');
echo $finfo->buffer($buffer) . "\n";
$buffer = file_get_contents('./Test.svg');
echo $finfo->buffer($buffer) . "\n";


Expected result:
----------------
image/svg+xml
image/svg+xml
image/svg+xml; charset=us-ascii
image/svg+xml; charset=utf-8


Actual result:
--------------
image/svg
image/svg+xml
image/svg; charset=us-ascii
image/svg+xml; charset=utf-8


-- 
Edit bug report at https://bugs.php.net/bug.php?id=79045&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=79045&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=79045&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=79045&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=79045&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=79045&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=79045&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=79045&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=79045&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=79045&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=79045&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=79045&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=79045&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=79045&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=79045&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=79045&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=79045&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=79045&r=mysqlcfg


Thread (12 messages)

« previous php.bugs (#224604) next »