Re: fuzzing lame

Thomas Orgis <[email protected]>
Newsgroups gmane.comp.audio.mp3.lame
Message-ID <20150221002827.09427f58@dunkelstern>
Am Fri, 20 Feb 2015 16:55:14 +0100
schrieb Alexander Leidinger <[email protected]>: 

> For the MP3 decoding part it also depends where the problems are, maybe
> it would be better to spend time to update the decoding part from
> upstream, than to fix existing problems. But again, we're low on active
> people...

I have a hard time imagining crashing lame via fuzzed PCM data (you did
test with random noise, right?;-), so would assume the MP3 input part,
too.

There were some crashes discovered in mpg123 in 2009 via fuzzed input
and fixed since then. It's possible that those very same issues are
present in the mpglib in lame. In case the very same samples still
manage to crash mpg123, too, I'd be interested, too, of course.

Regarding updating the decoder part with current mpg123: AFAIR, there
is still that interfacing for the frame analyzer (?) missing. I guess I
need to get up and dig into the Lame code for that.


Alrighty then,

Thomas

------------------------------------------------------------------------------
Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
from Actuate! Instantly Supercharge Your Business Reports and Dashboards
with Interactivity, Sharing, Native Excel Exports, App Integration & more
Get technology previously reserved for billion-dollar corporations, FREE
http://pubads.g.doubleclick.net/gampad/clk?id=190641631&iu=/4140/ostg.clktrk

_______________________________________________
Lame-dev mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/lame-dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.