[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: Tue, 19 Aug 2008 18:22:57 +0200
From: Nico Golde <oss-security+ml@...lde.de>
To: oss-security@...ts.openwall.com
Subject: Re: swfdec 0.6.8 stable update
Hi Marcus,
* Marcus Meissner <meissner@...e.de> [2008-08-19 16:48]:
> Wonder if we should track updates for swfdec. The 0.6.8 announcement
> looks like it at least fixes several Denial of Service problems:
[...]
I have problems to understand why this would be a Denial of
Service. While I don't share the opinion about browser
crashes I think there are at least good arguments for both
sides.
But if swfdec crashes on playing a flash movie this
looks like an application bug. At least I wouldn't talk
about Denial of Service if vim would crash on opening a text
file.
It would be interesting what is causing this crash and if
there is underlying a more serious issue.
Kind regards
Nico
--
Nico Golde - http://www.ngolde.de - nion@...ber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux