[vorbis-dev] Will Vorbis happily decode packets with random data?

Jack Moffitt jack at xiph.org
Wed Aug 8 09:04:11 PDT 2001



> So, it's not the output of the vorbis decoder I'm worried about; it's
> storing the vorbis file on the hard drive, if it's not really a vorbis
> file at all.

Then this is a general security risk, and not at all related to Vorbis.
It could be a .wav file, or a .jpg or whatever.  As long as it can be
transformed into the executable.  A valid vorbis file (ie, has correct
headers) will not be a valid executable.  

jack.

--- >8 ----
List archives:  http://www.xiph.org/archives/
Ogg project homepage: http://www.xiph.org/ogg/
To unsubscribe from this list, send a message to 'vorbis-dev-request at xiph.org'
containing only the word 'unsubscribe' in the body.  No subject is needed.
Unsubscribe messages sent to the list will be ignored/filtered.



More information about the Vorbis-dev mailing list