Bug/exploit in Monkey's Audio library, tag parser related |
![]() ![]() |
Bug/exploit in Monkey's Audio library, tag parser related |
Jan 1 2006, 21:22
Post
#1
|
|
![]() Group: Admin Posts: 3226 Joined: 30-September 01 Member No.: 84 |
Monkey's Audio decoder library 3.99 crashes when parsed file has more than 256 fields in the tag. Reproduced with Monkey's Audio frontend 3.99 and foobar2000 0.9 beta 13 (other versions are not vulnerable because offending APE tag parser was stripped down since a more serious security hole was found in it long ago; a fix will be uploaded soon).
-------------------- This job would be great if it wasn't for the users.
|
|
|
|
Jan 2 2006, 20:13
Post
#2
|
|
|
Group: Members Posts: 238 Joined: 22-February 04 Member No.: 12193 |
Sad
I have the feeling that Monkey's Audio isn't supported any more... Am I wrong ? |
|
|
|
Jan 2 2006, 20:25
Post
#3
|
|
![]() Group: Members Posts: 1394 Joined: 20-December 01 From: seattle Member No.: 693 |
it isn't officially...
but many people are keeping it alive (i.e. mac-port @ http://sourceforge.net/projects/mac-port) later -------------------- RareWares/Debian :: http://www.rarewares.org/debian.html
|
|
|
|
![]() ![]() |
|
Lo-Fi Version | Time is now: 21st May 2013 - 10:46 |