|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #69706 getimagesize() can fail if the underlying stream doensn't support seeking
Submitted: 2015-05-25 18:29 UTC Modified: 2020-04-02 11:25 UTC
Avg. Score:4.4 ± 0.9
Reproduced:9 of 9 (100.0%)
Same Version:4 (44.4%)
Same OS:2 (22.2%)
From: deviantintegral at gmail dot com Assigned: cmb (profile)
Status: Feedback Package: GetImageSize related
PHP Version: 5.6.9 OS: Any
Private report: No CVE-ID: None
Have you experienced this issue?
Rate the importance of this bug to you:

 [2015-05-25 18:29 UTC] deviantintegral at gmail dot com
I've verified this is an issue on PHP 5.4, 5.6, and statically on the master branch.

The AWS SDK ( includes a stream wrapper that by default does not support seeking on files backed by S3. Calling getimagesize() on an image can fail if php_skip_variable() is called. I've seen this happen with images that specify the "Image Quality" EXIF tag, which is the M_APP15 constant in ext/standard/image.c.

The stream documentation states that seeking is not required to be supported by stream wrappers, and it's not clear that getimagesize() needs seeking to work properly.

I see two ways to improve this:

* Log a notice if php_skip_variable() tries to seek on an unseekable stream. That would have saved me a ton of time tracing this with GDB.
* Or, if a stream is not seekable, copy the file to the temporary file system and fetch metadata from there. 


Add a Patch

Pull Requests

Add a Pull Request


AllCommentsChangesGit/SVN commitsRelated reports
 [2020-04-02 11:25 UTC]
-Status: Open +Status: Feedback -Assigned To: +Assigned To: cmb
 [2020-04-02 11:25 UTC]
For SEEK_CUR and positive offsets, non-seekable streams are
supposed to be read (discarding what was written).  So if you can
still reproduce this issue with any of the actively supported PHP
versions[1], please provide a minimal self-contained reproduce

[1] <>
PHP Copyright © 2001-2020 The PHP Group
All rights reserved.
Last updated: Thu Apr 09 05:01:23 2020 UTC