On Tue, 8 Dec 2009, Ralf Wildenhues wrote:
interfaces.  For example, it is already known that the .la file
parser is fragile and trivial edits to an .la file will cause the
using program to core-dump.  The .la file parsing is an external
interface so it should get more priority.

Good idea.  Proposed patch.  What other things do you know about that
are mishandled?

OK to commit?

The fix and the tests look quite good and useful to me. I don't currently know of other parsing issues.

As long as the application can trust that libltdl will search for .la files in secure locations, then there should not be great concern about corrupted .la files.

Bob
--
Bob Friesenhahn
bfrie...@simple.dallas.tx.us, http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/


Reply via email to