Open GoogleCodeExporter opened 9 years ago
I meant, "PDFium wrongly accepts direct stream objects"
Original comment by cork...@google.com
on 3 Jun 2015 at 7:26
What's the harm in doing this other than non-conformance with the spec?
Can we prove that there aren't any tools in the world that generate such files?
If there are, we'd break some otherwise displayable documents, no?
Original comment by tsepez@chromium.org
on 4 Jun 2015 at 7:29
AFAIK only PDF-ium accepts this (it's very far from the official specs),
which I've never seen in the wild, malware or clean files.
If it's so broken, I see it as a security filter bypass.
Original comment by cork...@google.com
on 5 Jun 2015 at 8:36
Ah. Do you know of any filters that are both
1) effective and
2) impacted by this?
Original comment by tsepez@chromium.org
on 9 Jun 2015 at 6:08
Original issue reported on code.google.com by
cork...@google.com
on 3 Jun 2015 at 6:56Attachments: