Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 23 Aug 2008 11:58:52 +0200
From: Marcus Meissner <meissner@...e.de>
To: oss-security@...ts.openwall.com
Subject: Re: swfdec 0.6.8 stable update

On Tue, Aug 19, 2008 at 06:22:57PM +0200, Nico Golde wrote:
> Hi Marcus,
> * Marcus Meissner <meissner@...e.de> [2008-08-19 16:48]:
> > Wonder if we should track updates for swfdec. The 0.6.8 announcement
> > looks like it at least fixes several Denial of Service problems:
> [...] 
> I have problems to understand why this would be a Denial of 
> Service. While I don't share the opinion about browser 
> crashes I think there are at least good arguments for both 
> sides.

If it can be triggered by a SWF on the website, I would perhaps
call it a security issue.

If it crashes the SWF mozilla plugin and so the browser, it is
a denial of service in my eyes.

More importantly if code execution is possible.


I have however not researched those further (just saw the changelog as
packager of swfdec), and currently swfdec itself is probably not yet
fully production ready anyway.

> But if swfdec crashes on playing a flash movie this 
> looks like an application bug. At least I wouldn't talk 
> about Denial of Service if vim would crash on opening a text 
> file.

Yeah.

> It would be interesting what is causing this crash and if 
> there is underlying a more serious issue.

Not really investigated and no time :/ Since swfdec is beta and not yet
wildy iin use we could let it rest.

Ciao, Marcus

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.