Re: [security-report]Lame multi memory error bug && CVE Request
Alexander Leidinger <[email protected]>
| Newsgroups | gmane.comp.audio.mp3.lame |
|---|---|
| Message-ID | <[email protected]> |
On Sun, 07 Feb 2016 17:17:15 +0100 Fabian Greffrath <[email protected]> wrote: > Hi there, > > during the last year or so, a lot of crashes like the one you > experienced have been reported against the "lame" package in Debian. > They were all triggered by fuzzed input data and led to segmentation > faults and stack corruption. Meanwhile, we have been able to fix all > of them (i.e. the ones that were reported). The individual patches > can be found here, they have all been already applied to the lame CVS > head (thanks to rbrito): Hi Fabian, are there some patches which are not in CVS but would be important to have in CVs (not only for debian)? In the LAME CVS I changed configure to not silence the assert()s in the code when doing a release-build. Not a nice error message when a corrupt input is detected, but at least a defined one. Maybe you want to check if this is something to add to debian until we have a new release. Bye, Alexander. -- http://www.Leidinger.net [email protected]: PGP 0xC773696B3BAC17DC http://www.FreeBSD.org [email protected] : PGP 0xC773696B3BAC17DC ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140