Re: prominent message on website about "use only on trusted input"?

electricworry <[email protected]> Fri, 28 Jul 2017 12:51:00 +0100
Newsgroups gmane.comp.audio.mp3.lame
Message-ID <CABZPTZSbtii6CJgsaF5hPSj_3ovqj1p8r8NeROJrCWX_ZYS=MQ@mail.gmail.com>
On 28 July 2017 at 10:56, Alexander Leidinger <[email protected]> wrote:
> given the recent messages about more attention by security researchers to
> LAME, I suggest we add a prominent message (maybe even on the main page)
> about using LAME only on trusted input.
>
> For me LAME was never developed with security in mind, just to be used on
> trusted input (letting aside the question what trusted input is after the
> rootkit-mistake Sony did in the past).
>
> Comments?

If I may chime in, I would say that the security of LAME seems good.
None of the issues I've seen allow for any remote code execution. At
best they can crash the program (probably getting a CVSS score of
around 2.5) or they only crash the program if caught by address
sanitizer (so a normal build would get a CVSS score of 0.0).

What would you be trying to achieve with such a disclaimer. If it's to
avoid claims of liability, that's understandable but I would imagine
you've already got that in the license already.

If it's to protect the project from the work of having to deal with
reports of security type issues, then I'm not sure that's a great
idea. At some level, the LAME project wants to be used and trusted
widely, and if a project was to ignore security reports, I think
that's a problem for distros and other adopters. I think the best
approach would be to deal with these small issues with the priority
they deserve (low or none). I also think/hope that in the unlikely
event of a higher severity remote code execution that you would want
to resolve that.

Just my two cents...

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot