Re: prominent message on website about "use only on trusted input"?
electricworry <[email protected]> Fri, 28 Jul 2017 12:51:00 +0100
| Newsgroups | gmane.comp.audio.mp3.lame |
|---|---|
| Message-ID | <CABZPTZSbtii6CJgsaF5hPSj_3ovqj1p8r8NeROJrCWX_ZYS=MQ@mail.gmail.com> |
On 28 July 2017 at 10:56, Alexander Leidinger <[email protected]> wrote: > given the recent messages about more attention by security researchers to > LAME, I suggest we add a prominent message (maybe even on the main page) > about using LAME only on trusted input. > > For me LAME was never developed with security in mind, just to be used on > trusted input (letting aside the question what trusted input is after the > rootkit-mistake Sony did in the past). > > Comments? If I may chime in, I would say that the security of LAME seems good. None of the issues I've seen allow for any remote code execution. At best they can crash the program (probably getting a CVSS score of around 2.5) or they only crash the program if caught by address sanitizer (so a normal build would get a CVSS score of 0.0). What would you be trying to achieve with such a disclaimer. If it's to avoid claims of liability, that's understandable but I would imagine you've already got that in the license already. If it's to protect the project from the work of having to deal with reports of security type issues, then I'm not sure that's a great idea. At some level, the LAME project wants to be used and trusted widely, and if a project was to ignore security reports, I think that's a problem for distros and other adopters. I think the best approach would be to deal with these small issues with the priority they deserve (low or none). I also think/hope that in the unlikely event of a higher severity remote code execution that you would want to resolve that. Just my two cents... ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot