[Pkg-privacy-maintainers] Bug#826101: mat doesn't remove metadata in embedded images in PDFs

Petter Reinholdtsen pere at hungry.com
Sun Aug 21 22:29:43 UTC 2016


[Holger Levsen 2016-06-02]
> https://digitalcourage.de/blog/2016/using-tails-be-careful-embedded-metadata
> explains how mat fails to do what it's supposed to do, namely removing
> embedded meta data.
> 
> I havent't verifed this myself, but appearantly it doesnt remove
> metadata from images embedded in PDFs.
> 
> So basically the core feature of mat is partly broken :/

Reading the upstream bug report, there seem to be no solution in sight
any time soon.  Perhaps it would be better if mat simply reported a
failure and refused to process the input if it find embedded parts it
can't strip?  It would be better than pretending to succeed.

> I wonder if similar bugs happen with other recursive formats, like an
> OpenDocument text embedding an image or embedding a pdf embedding an
> image or a zip file containing a zip file containing a .odt file
> containing an pdf containing an image???

No idea, but it would be useful to check. :)

Did you ever get a CVE for this issue?  I did not find one when I followed
the mailing list thread, but might have missed it.

-- 
Happy hacking
Petter Reinholdtsen



More information about the Pkg-privacy-maintainers mailing list