I'd accept this for maybe pre-2000, but people should really know better.
this doesn't work in perl 5.6.2! grrrr
So this code is at least 20 years old, and probably pre-2000. Sept. 26, 2008 - Version 7.44
- Added read support for DjVu images
There were probably enough systems running perl 5.6.2 around 2008 to cause bug reports, or the code was migrated from an older piece of code and added to ExifTool.It was not uncommon to manually ./configure, make, make install tarballs locally in those days, especially not on systems like Slackware so I can see it being possible to have old packages installed that were not automagically updated.
I looked at the front-page of that library. It says it cleans metadata from a huge number of file format. Frankly it looks more like something you would use on your own, known safe, files before sharing them online.
I'm not sure the tool is presented as a sanitizer for untrusted input. At least, it does not claim to be.
Why does Gitlab need to clean metadata from DjVu files? Wtf are DjVu files?!
It doesn't. It needs to clean metadata from JPEG and TIFF files. They didn't properly check if the files were actually of those types, and Exiftool performed its own content type detection to end up in its DjVu code.
> Wtf are DjVu files?!
DjVu is basically an alternative to PDF.[1]