Re: LAME oss-fuzz integration
Alexander Leidinger via Lame-dev <[email protected]> Sat, 23 Mar 2019 17:38:33 +0100
| Newsgroups | gmane.comp.audio.mp3.lame |
|---|---|
| Message-ID | <20190323173833.Horde.agpRCCdAB-PBYyetcKGfLte@webmail.leidinger.net> |
Quoting Guido Vranken <[email protected]> (from Tue, 19 Mar 2019 11:41:32 +0100): > Dear list, > > oss-fuzz is a Google initiative that performs continuous fuzz testing on > widely used open source software in pursuit of discovering software > vulnerabilities like buffer overflows. > > I've written a LAME fuzzer that I can request to be merged into oss-fuzz. > > Is the LAME development team interested in oss-fuzz integration? In general it is off course beneficial to have such support. It finds bugs, and we want to have bugs fixed. > Please see here what oss-fuzz expects from upstream developers: > https://github.com/google/oss-fuzz/blob/master/README.md I had a look at this when Google announced it. I do not expect that we can meet the requirements about responsiveness. "make public" latest after 90 days is implying that every issue found is interpreted as a security issue (which in general it may or may not be). Due to the fact that the LAME project always tells to use LAME on trusted input (we don't support music piracy) and as such every input to LAME is by definition not malicious and not a security issue (just a bug we off course want to fix). The perceptions differ here and the press will off course make headlines without looking if we also consider this as a security issues or not. > If you are keen, then for now I only need one or more developer e-mail > addresses that are linked to a Google account, and I will take care of the > integration. I think we should integrate the necessary code changes in the LAME source (best would be a patch in https://sourceforge.net/p/lame/patches/ and a little mail to this list to inform about it), but if nobody from the team stands up and tells that he is willing to tackle issues in-time, or at least monitor and act on it in an OKish timeframe, I don't think we can provide such an e-mail address. > On a related note, I've found a memory corruption bug with my fuzzer in the > LAME encoder. Do you prefer that I post bug details to this public list, or > should I report it to a specific address? Please file a bug report at https://sourceforge.net/p/lame/bugs/ or maybe if you even have a patch, then use https://sourceforge.net/p/lame/patches/ for it. Bye, Alexander. -- http://www.Leidinger.net [email protected]: PGP 0x8F31830F9F2772BF http://www.FreeBSD.org [email protected] : PGP 0x8F31830F9F2772BF