Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 14 Sep 2017 11:51:42 +0200
From: "Dr. Thomas Orgis" <thomas.orgis@...-hamburg.de>
To: oss-security@...ts.openwall.com
Subject: Re: mp3gain: NULL pointer dereference in sync_buffer
 (mpglibDBL/interface.c)

Am Thu, 14 Sep 2017 09:51:36 +0200
schrieb Agostino Sarubbo <ago@...too.org>:

> Anwyay I agree with you that is time to drop the packages.

I disagree. I am considering cleaning up mp3gain and omitting nearly
all of the vulnerabilities by removing the decoder fork. Reason: rgain
does not do what mp3gain did. Mp3gain can directly modify the MPEG
frames so that the gain is changed also for decoders that do not
support the added metadata (it additionally stores metadata to be able
to revert the changes).

While I am not regularily using this myself, I do think that it's a
nifty hack that should not disappear. Maybe it can re-enter distros if
it does not rely on an outdated internal decoder … 

This is becoming a bit off-topic … but I just wanted to note that the
bug reports do serve a purpose in alerting me to that other copy of
mpg123 code in the wild.


Alrighty then,

Thomas

-- 
Dr. Thomas Orgis
Universität Hamburg
RRZ / Basis-Infrastruktur / HPC
Schlüterstr. 70
20146 Hamburg
Tel.: 040/42838 8826
Fax: 040/428 38 6270

Download attachment "smime.p7s" of type "application/pkcs7-signature" (4967 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.