Re: fuzzing lame
Thomas Orgis <[email protected]>
| Newsgroups | gmane.comp.audio.mp3.lame |
|---|---|
| Message-ID | <20150221002827.09427f58@dunkelstern> |
Am Fri, 20 Feb 2015 16:55:14 +0100 schrieb Alexander Leidinger <[email protected]>: > For the MP3 decoding part it also depends where the problems are, maybe > it would be better to spend time to update the decoding part from > upstream, than to fix existing problems. But again, we're low on active > people... I have a hard time imagining crashing lame via fuzzed PCM data (you did test with random noise, right?;-), so would assume the MP3 input part, too. There were some crashes discovered in mpg123 in 2009 via fuzzed input and fixed since then. It's possible that those very same issues are present in the mpglib in lame. In case the very same samples still manage to crash mpg123, too, I'd be interested, too, of course. Regarding updating the decoder part with current mpg123: AFAIR, there is still that interfacing for the frame analyzer (?) missing. I guess I need to get up and dig into the Lame code for that. Alrighty then, Thomas ------------------------------------------------------------------------------ Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server from Actuate! Instantly Supercharge Your Business Reports and Dashboards with Interactivity, Sharing, Native Excel Exports, App Integration & more Get technology previously reserved for billion-dollar corporations, FREE http://pubads.g.doubleclick.net/gampad/clk?id=190641631&iu=/4140/ostg.clktrk _______________________________________________ Lame-dev mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/lame-dev