[vorbis-dev] Will Vorbis happily decode packets with random data?

Gian-Carlo Pascutto gcp at sjeng.org
Fri Aug 10 11:52:51 PDT 2001



On Wed, 8 Aug 2001, Monty wrote:

> Static buffers have been a known risk for 20 years and only lazy,
> piss-poor programmers (the majority, I grant you) would write code
> today that could be overrun.  If you can find a buffer overrun in
> Vorbis, a case of whatever brew you prefer is on me.

Hmm, latest CVS of your branch segfaults in malloc when a
nonstandard blocksize is used (instead of 256/2048).

Earlier versions handled this just fine.

(Dunno if it's a real overrun, but for a case at stake I'd
at least mention it :)


-- 
GCP

--- >8 ----
List archives:  http://www.xiph.org/archives/
Ogg project homepage: http://www.xiph.org/ogg/
To unsubscribe from this list, send a message to 'vorbis-dev-request at xiph.org'
containing only the word 'unsubscribe' in the body.  No subject is needed.
Unsubscribe messages sent to the list will be ignored/filtered.




More information about the Vorbis-dev mailing list