Re: fuzzing lame

Alexander Leidinger <[email protected]>
Newsgroups gmane.comp.audio.mp3.lame
Message-ID <[email protected]>
On Sat, 14 Feb 2015 12:01:52 +0200
Henri Salo <[email protected]> wrote:

> Hi,
> 
> I found lots of crashes when testing lame using a fuzzer. Who is the
> correct person to coordinate these or should I just file bugs to
> http://sourceforge.net bug tracker? Some of these might have security
> implications.

In general:
 - security issues should be handled in a secure way
 - we are low on active members
 - we don't really have a security contact


Based upon this, my personal point of view:
 - lame is not a player and as such has less of such an target audience
 - we haven't announced it explicitly, but we never did a security
   audit of the code, as such I wouldn't be surprised if there are
   issues in this regard, and anyone with just a little bit of security
   background will see this when reading the commit logs
 - I would assume it is less common that someone downloads something
   from an untrusted source and re-encodes it, than someone creates
   original content and produces an MP3 or someone rips a CD and
   generates a MP3 for personal use
 - yes, I'm aware now with CC licensed music the chance that someone
   downloads something from an untrusted source and uses it to create
   his own content he then feeds to lame is higher than years ago, but
   I would expect that the decoding happens in some other code

As such I'm inclined to say that normal bugreports are enough... but
only as we are low on active people (me included).

For the MP3 decoding part it also depends where the problems are, maybe
it would be better to spend time to update the decoding part from
upstream, than to fix existing problems. But again, we're low on active
people...

For problems in the WAV input path we surely should fix problems. My
expectation here is that WAVs are more used with original content from
trusted sources, than something coming from an untrusted stranger.

So while there may be security implications, we don't have the
man-power to handle them like they shall be handled, and as such we
don't have other options left than to add them as normal bug reports.

Bye,
Alexander.

-- 
http://www.Leidinger.net [email protected]: PGP 0xC773696B3BAC17DC
http://www.FreeBSD.org    [email protected]  : PGP 0xC773696B3BAC17DC

------------------------------------------------------------------------------
Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
from Actuate! Instantly Supercharge Your Business Reports and Dashboards
with Interactivity, Sharing, Native Excel Exports, App Integration & more
Get technology previously reserved for billion-dollar corporations, FREE
http://pubads.g.doubleclick.net/gampad/clk?id=190641631&iu=/4140/ostg.clktrk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.