prominent message on website about "use only on trusted input"?

Alexander Leidinger <[email protected]> Fri, 28 Jul 2017 11:56:55 +0200
Newsgroups gmane.comp.audio.mp3.lame
Message-ID <20170728115655.Horde.7UnlKO4o_BStXn_OmQPShG6@webmail.leidinger.net>
Hi,

given the recent messages about more attention by security researchers  
to LAME, I suggest we add a prominent message (maybe even on the main  
page) about using LAME only on trusted input.

For me LAME was never developed with security in mind, just to be used  
on trusted input (letting aside the question what trusted input is  
after the rootkit-mistake Sony did in the past).

Comments?

What I propose is something like this (improvements more than welcome):
---snip---
[red]Security notice:[/red] [bold]only use LAME on trusted  
input[/bold], e.g. something you created on your own. LAME was and is  
developed with MP3 encoding / research in mind, not with best seucrity  
principles. Security issues are off course issues which shall be  
fixed, but given the nature of things (e.g. copyright laws (which  
affects what you are legally allowed to feed to LAME) and availability  
of time of the developers of LAME), seucrity is not the number one  
priority.

Note to security researchers: there was never a security review of the  
code of LAME (at least we are not aware of one). As such we would not  
be surprised if it is easy to find security issues. We welcome off  
course responsible security disclosure, but given the available /  
active resources working on LAME, we can not promise timely responses  
/ fixes. As such we will not complain about a reduced "timeout from  
LAME project" in your responsible disclosure process, but ask you to  
provide a way to reproduce the issue (e.g. a small sample input file  
which leads to a segfault, not a full exploit) before publishing  
issues. It may also be a good idea to notify GNU/Linux / *BSD  
distributions which ship binary packages of LAME in advance in case  
they want to create fixes before the issue is published.
---snip---

What do you think?

Bye,
Alexander.

-- 
http://www.Leidinger.net [email protected]: PGP 0x8F31830F9F2772BF
http://www.FreeBSD.org    [email protected]  : PGP 0x8F31830F9F2772BF
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.