[Mimedefang] Re: Image spam and broken file formats

David F. Skoll dfs at roaringpenguin.com
Tue Dec 5 20:47:08 EST 2006

Kenneth Porter wrote:

> What I'm thinking might be low-hanging fruit is bad headers, data beyond
> the end of the format, and compression bombs.

I'm not very familiar with GIF and JPEG, but I have worked extensively
with TIFF.  With a TIFF image, you can play many wacky tricks and
stuff data in the image file in countless weird ways.  I don't know if
it's possible to "validate" a TIFF image.

JPEG and GIF are much simpler, but I bet they're still complex
enough to make validation iffy.



