Re: [security-report]Lame multi memory error bug && CVE Request

Alexander Leidinger <[email protected]>
Newsgroups gmane.comp.audio.mp3.lame
Message-ID <[email protected]>
On Sat, 2 Jan 2016 00:31:05 -0800
Eric Stargardt <[email protected]> wrote:

> I'm sorry, but I just feel it necessary to give my opinion here.  It
> is absolutely legal and tested in the courts, for any individual or
> entity to copy and convert copyrighted media for which they hold a
> license to (ie, a CD) into alternate formats for backup and playback
> that does not copy beyond the original license holder.

I would hope that a ripped CD I bought will be trusted input. If a
company publishes an audio CD which will install malicious software via
a LAME code bug when an audio track is encoded, then we are in a very
bad world (this would go far far far far beyond what Sony did with the
"root-kit copy protection").

The report was not about such files. To me it looks the input in
the report which triggers the issue is specially crafted to cause this
issue.

What I had in mind are not normal audio files you get when you buy
copyrighted material. What I had in mind was illegally downloading
audio/movies from a source you know nothing about and then re-encode
it. So it is really about someone manipulating the input in a malicious
way which would not happen with a normal audio input.


> 
> That said, it is a poor argument to excuse a security flaw as some
> kind of moral reckoning for those who would break the law.

LAME is not a remotely exposed software like a webserver, a mail user
agent, a mail server or a web-application. All those programs are
exposed to input you can't control by definition and need to be able
to cope with that. Any security issue there calls for a CVE.

LAME is not in the same security class. It is not designed to handle
untrusted input. Yes, it would be nice if it could, unfortunately the
reality is different. Any legal audio input from an audio CD or
blue-ray or DVD will not trigger this issue. Again, I only speak for
me, not for other project members.

Yes, we want to fix this issue. If you look at the activity of the LAME
project, I would not expect a fast fix within a day.

Bye,
Alexander.

-- 
http://www.Leidinger.net [email protected]: PGP 0xC773696B3BAC17DC
http://www.FreeBSD.org    [email protected]  : PGP 0xC773696B3BAC17DC

------------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.