Erik de Castro Lopo wrote: > For Linux distributions, the specific fixes for these two CVEs are available > from Git here: > > > https://git.xiph.org/?p=flac.git;a=commit;h=fcf0ba06ae12ccd7c67cee3c8d948df15f946b85
A comment in the code about the patch: "We have received a potentially malicious bt stream" What "bt stream" means? or is it a typo (and it is "bit stream")? Also, in AUTHORS file: "Website : https://www.xip.org/flac/" xip -> xiph. So it's "https://www.xiph.org/flac/" (or maybe "http://www.xiph.org/flac/" or "http://xiph.org/flac/") _______________________________________________ flac-dev mailing list flac-dev@xiph.org http://lists.xiph.org/mailman/listinfo/flac-dev