On Sat, Feb 11, 2017 at 11:21 AM, Diego Biurrun <[email protected]> wrote:
> This avoids (mis)detection of severely damaged or fuzzed streams and
> all sorts of crashes or failures down the line.
>
> Bug-Id: 1027
> ---
>
> I have no idea how many (or any at all) real AAC streams this might stop
> from being detected, but trying not to crash in damaged or malicious
> streams down the line is a game of whack-a-mole that is IMO impossible
> to win...
>

This doesn't remove any requirements of hardening the decoders, I
could easily craft a file with 5 valid frames and then the same
garbage, so that argument seems a bit silly.

- Hendrik
_______________________________________________
libav-devel mailing list
[email protected]
https://lists.libav.org/mailman/listinfo/libav-devel

Reply via email to