1
0
mirror of https://github.com/cdcseacave/TinyEXIF.git synced 2026-07-21 11:13:01 +04:00
cDc b6ea1b7bbe Fix possible integer overflow in parseString bounds check (#26)
* Fix integer overflow in parseString bounds check

Cast `base` to `uint64_t` in the parseString bounds check
`base+data+num_components <= len` to prevent unsigned integer overflow.

When `data` is attacker-controlled (e.g. 0xffffffff), the 32-bit
unsigned addition wraps around, causing the check to pass even though
the computed offset is far beyond the buffer. This leads to an
out-of-bounds heap read or segfault when dereferencing the resulting
pointer.

Fixes #16

* Fix type casting for base pointer comparison
2026-03-19 06:55:25 +02:00
2025-11-17 19:12:20 +02:00
2025-11-17 17:48:29 +02:00
2025-11-17 18:47:27 +02:00
2025-11-17 19:12:20 +02:00
2025-11-17 17:48:29 +02:00
2025-11-17 18:04:59 +02:00
2025-11-17 18:04:59 +02:00
2019-01-11 15:24:23 +02:00
2025-11-17 18:47:27 +02:00
2025-11-17 19:12:20 +02:00

TinyEXIF: Tiny ISO-compliant C++ EXIF and XMP parsing library for JPEG

Introduction

TinyEXIF is a tiny, lightweight C++ library for parsing the metadata existing inside JPEG files. No third party dependencies are needed to parse EXIF data, however for accesing XMP data the TinyXML2 library is needed. TinyEXIF is easy to use, simply copy the two source files in you project and pass the JPEG data to EXIFInfo class. Currently common information like the camera make/model, original resolution, timestamp, focal length, lens info, F-stop/exposure time, GPS information, etc, embedded in the EXIF/XMP metadata are fetched. It is easy though to extend it and add any missing or new EXIF/XMP fields.

Usage example

#include "TinyEXIF.h"
#include <iostream> // std::cout
#include <fstream>  // std::ifstream
#include <vector>   // std::vector

int main(int argc, const char** argv) {
	if (argc != 2) {
		std::cout << "Usage: TinyEXIF <image_file>" << std::endl;
		return -1;
	}

	// open a stream to read just the necessary parts of the image file
	std::ifstream istream(argv[1], std::ifstream::binary);

	// parse image EXIF and XMP metadata
	TinyEXIF::EXIFInfo imageEXIF(istream);
	if (imageEXIF.Fields)
		std::cout
			<< "Image Description " << imageEXIF.ImageDescription << "\n"
			<< "Image Resolution " << imageEXIF.ImageWidth << "x" << imageEXIF.ImageHeight << " pixels\n"
			<< "Camera Model " << imageEXIF.Make << " - " << imageEXIF.Model << "\n"
			<< "Focal Length " << imageEXIF.FocalLength << " mm" << std::endl;
	return 0;
}

See main.cpp for more details.

License

MIT License

Copyright (c) 2025 cdcseacave

Acknowledgments

Inspired by easyexif library (2013 version) of Mayank Lahiri (mlahiri@gmail.com).

S
Description
No description provided
Readme MIT 24 MiB
Languages
C++ 94.4%
CMake 4.7%
Python 0.9%