[Theora] Other extension for Ogg Theora then "ogg"

Jack Moffitt jack at xiph.org
Mon May 9 16:10:58 PDT 2005


> If it was "smart" and looked inside (like what you and many others 
> recommend), then that  "Nasty-Virus.jpg" would be recognized as an 
> executable and be run, instead of being displayed as a broken picture.

Not true.  As I understand it, many of these bugs were the fact that
once the app saw the jpeg extension, it passed off the file to a generic
"open" call which would use content based methods to determine the type
and then open it appropriately.  What this means is that you could
rename an exe to a jpg, and it would get opened and executed.

That said, I'm sure there are vulnerabilities of the type you suggest as
well.

Windows Media player and many other media players already ignore
extensions anyway, since much of hte content coming off of file sharing
networks is misnamed.  Regardless of extension (as long as the extension
is one assigned to media player), media player seems to be able to play
all files even if the extension lies.

jack.


More information about the Theora mailing list