Re: multiple crashes in lame

Thomas Orgis <[email protected]>
Newsgroups gmane.comp.audio.mp3.lame
Message-ID <20170629150940.4c36a57d@sturbolzen>
Am Wed, 28 Jun 2017 16:10:48 +0200
schrieb Agostino Sarubbo <[email protected]>: 

> https://blogs.gentoo.org/ago/2017/06/17/lame-global-buffer-overflow-in-ii_step_one-layer2-c
> 
> https://blogs.gentoo.org/ago/2017/06/17/lame-global-buffer-overflow-in-iii_i_stereo-layer3-c
> 
> https://blogs.gentoo.org/ago/2017/06/17/lame-stack-based-buffer-overflow-in-iii_i_stereo-layer3-c
> 
> https://blogs.gentoo.org/ago/2017/06/17/lame-stack-based-buffer-overflow-in-iii_dequantize_sample-layer3-c

This is a good opportunity to finally get the mpglib fork in lame
replaced with libmpg123. I know we're short on developer time here …
but could someone at least point out what additions to the libmpg123
API (http://mpg123.org/api/) are needed to replace lame's fork? There
were needs for some frame analyser tool … worst case would be mapping
this part to libmpg123 API that simply gives you access the raw frame
data. The decoding aspect of mpglib, which contains the above-mentioned
bugs, can be replaced with less effort, I presume.


Alrighty then,

Thomas
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Lame-dev mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/lame-dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.