Welcome Guest ( Log In | Register )

Reply to this topicStart new topic
Bug/exploit in Monkey's Audio library, tag parser related
post Jan 1 2006, 21:22
Post #1

foobar2000 developer

Group: Admin
Posts: 3359
Joined: 30-September 01
Member No.: 84

Monkey's Audio decoder library 3.99 crashes when parsed file has more than 256 fields in the tag. Reproduced with Monkey's Audio frontend 3.99 and foobar2000 0.9 beta 13 (other versions are not vulnerable because offending APE tag parser was stripped down since a more serious security hole was found in it long ago; a fix will be uploaded soon).
Go to the top of the page
+Quote Post
post Jan 2 2006, 20:13
Post #2

Group: Members
Posts: 238
Joined: 22-February 04
Member No.: 12193

Sad sad.gif
I have the feeling that Monkey's Audio isn't supported any more... Am I wrong ?
Go to the top of the page
+Quote Post
post Jan 2 2006, 20:25
Post #3

Group: Members
Posts: 1394
Joined: 20-December 01
From: Bellingham, WA
Member No.: 693

it isn't officially...

but many people are keeping it alive (i.e. mac-port @ http://sourceforge.net/projects/mac-port)

Go to the top of the page
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:


RSS Lo-Fi Version Time is now: 1st December 2015 - 03:38