Re: CALL for DISCUSSION: eXIf 20170115

Glenn Randers-Pehrson <[email protected]>
Newsgroups gmane.comp.graphics.png.general
Message-ID <CA+PdXcvpe+rUp82P3X7jp2-GSObZ_J8Ttc5Qoo1Bv9o1Avi=WQ@mail.gmail.com>
On Wed, Feb 1, 2017 at 11:38 AM, John Bowler <
[email protected]> wrote:


>
> The most serious CVE level bug I remember was the one whereby
> decompression of the profile allowed a DoS attack either by running
> out of memory or via the "realloc" exploit which allowed an attacker
> to slow decoding of a single PNG to minutes.  This is why Glenn had to
> add the original profile length of the zXIf proposal, and why it was
> there from the start in the cOMp proposal.
>

In fact, that's an important lesson.  We should take permanent note,
somehow, to never approve a chunk that has compression but lacks
an "original length" field.  We've made that mistake before, but don't
need to make it again.  That does *not* rule out compression, though,
it just means that we must do it safely.

Glenn

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, SlashDot.org! http://sdm.link/slashdot

_______________________________________________
png-mng-misc mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/png-mng-misc
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.