Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 21 Mar 2012 16:42:38 +0100
From: Ludwig Nussel <>
Cc: Zubin Mithra <>,
	Kurt Seifried <>,
	Dhanesh k <>
Subject: Re: CVE-Request taglib vulnerabilities

Zubin Mithra wrote:
> [...]
> The issues which are present in the latest "release" but not in the current
> development head were :-
> [3] Lack of sanity checks of fields which were read, and were used for
> allocating memory; crafted files would lead of application crash.

Not an issue according to upstream:

> [4] A one bit change in a working ogg file would cause a thread to loop
> infinitely.


 (o_   Ludwig Nussel
SUSE LINUX Products GmbH, GF: Jeff Hawn, Jennifer Guild, Felix Imend├Ârffer, HRB 16746 (AG N├╝rnberg) 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.