IPB

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
Bug/exploit in Monkey's Audio library, tag parser related
Peter
post Jan 1 2006, 21:22
Post #1


foobar2000 developer


Group: Admin
Posts: 3275
Joined: 30-September 01
Member No.: 84



Monkey's Audio decoder library 3.99 crashes when parsed file has more than 256 fields in the tag. Reproduced with Monkey's Audio frontend 3.99 and foobar2000 0.9 beta 13 (other versions are not vulnerable because offending APE tag parser was stripped down since a more serious security hole was found in it long ago; a fix will be uploaded soon).
Go to the top of the page
+Quote Post
Zurman
post Jan 2 2006, 20:13
Post #2





Group: Members
Posts: 238
Joined: 22-February 04
Member No.: 12193



Sad sad.gif
I have the feeling that Monkey's Audio isn't supported any more... Am I wrong ?
Go to the top of the page
+Quote Post
xmixahlx
post Jan 2 2006, 20:25
Post #3





Group: Members
Posts: 1394
Joined: 20-December 01
From: seattle
Member No.: 693



it isn't officially...

but many people are keeping it alive (i.e. mac-port @ http://sourceforge.net/projects/mac-port)


later


--------------------
RareWares/Debian :: http://www.rarewares.org/debian.html
Go to the top of the page
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



RSS Lo-Fi Version Time is now: 29th July 2014 - 21:30