prominent message on website about "use only on trusted input"?
Alexander Leidinger <[email protected]> Fri, 28 Jul 2017 11:56:55 +0200
| Newsgroups | gmane.comp.audio.mp3.lame |
|---|---|
| Message-ID | <20170728115655.Horde.7UnlKO4o_BStXn_OmQPShG6@webmail.leidinger.net> |
Hi, given the recent messages about more attention by security researchers to LAME, I suggest we add a prominent message (maybe even on the main page) about using LAME only on trusted input. For me LAME was never developed with security in mind, just to be used on trusted input (letting aside the question what trusted input is after the rootkit-mistake Sony did in the past). Comments? What I propose is something like this (improvements more than welcome): ---snip--- [red]Security notice:[/red] [bold]only use LAME on trusted input[/bold], e.g. something you created on your own. LAME was and is developed with MP3 encoding / research in mind, not with best seucrity principles. Security issues are off course issues which shall be fixed, but given the nature of things (e.g. copyright laws (which affects what you are legally allowed to feed to LAME) and availability of time of the developers of LAME), seucrity is not the number one priority. Note to security researchers: there was never a security review of the code of LAME (at least we are not aware of one). As such we would not be surprised if it is easy to find security issues. We welcome off course responsible security disclosure, but given the available / active resources working on LAME, we can not promise timely responses / fixes. As such we will not complain about a reduced "timeout from LAME project" in your responsible disclosure process, but ask you to provide a way to reproduce the issue (e.g. a small sample input file which leads to a segfault, not a full exploit) before publishing issues. It may also be a good idea to notify GNU/Linux / *BSD distributions which ship binary packages of LAME in advance in case they want to create fixes before the issue is published. ---snip--- What do you think? Bye, Alexander. -- http://www.Leidinger.net [email protected]: PGP 0x8F31830F9F2772BF http://www.FreeBSD.org [email protected] : PGP 0x8F31830F9F2772BF ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot