Brian Willoughby wrote: > While we're on the topic, what sort of consequences are there, really, > with this vulnerability? Worst case, your player stops playing on a > file that cannot be played anyway. Yes, it's bad that you have to > power-cycle the player to get it to restart, but it's not like you > can be doing anything else at the same time you're playing a bad FLAC. > Have I missed something?
I think you are underestimating what a motivated cracker can do starting with a simple heap overflow. See: http://en.wikipedia.org/wiki/Heap_overflow Erik -- ---------------------------------------------------------------------- Erik de Castro Lopo http://www.mega-nerd.com/ _______________________________________________ flac-dev mailing list flac-dev@xiph.org http://lists.xiph.org/mailman/listinfo/flac-dev