Re: [pulseaudio-discuss] Vulnerability in Webkit-GTK and PulseAudio volume handling

2013-10-21 Thread Alexander E. Patrakov
2013/10/11 Xabier Rodríguez Calvar : > For Colin to know, before touching anything in WebKitGtk+ the behavior > was that the volume was ramping up to 100% with every website regardless > their volume control. > > I met Slomo and Lennart at GUADEC and we thought that the best was > letting the sink,

Re: [pulseaudio-discuss] Vulnerability in Webkit-GTK and PulseAudio volume handling

2013-10-11 Thread Xabier Rodríguez Calvar
O Xov, 10-10-2013 ás 20:50 +0100, Colin Guthrie escribiu: > It's certainly an interesting issue and your code highlights the > problem > quite well. > > I'm not sure I consider it a technical vulnerability tho' (just my > personal opinion) but I do appreciate the damage to both h/w and > hearing

Re: [pulseaudio-discuss] Vulnerability in Webkit-GTK and PulseAudio volume handling

2013-10-10 Thread Alexander E. Patrakov
Colin Guthrie wrote: What would be more interesting to me would be how the same code works on Windows 7 which I believe also implements a flat volume scheme (not sure about Win 8) and how it handles stream volumes in this context (background: http://www.patrickbaudisch.com/publications/2004-Ba

Re: [pulseaudio-discuss] Vulnerability in Webkit-GTK and PulseAudio volume handling

2013-10-10 Thread Colin Guthrie
Hi Alexander, 'Twas brillig, and Alexander E. Patrakov at 08/10/13 11:33 did gyre and gimble: > Note: this is not a CVE request yet! Before making a formal CVE request, > I would need to collect "official" information on the topic who needs to > do what with this bug (although I do have my own opi

[pulseaudio-discuss] Vulnerability in Webkit-GTK and PulseAudio volume handling

2013-10-08 Thread Alexander E. Patrakov
Hello. Note: this is not a CVE request yet! Before making a formal CVE request, I would need to collect "official" information on the topic who needs to do what with this bug (although I do have my own opinion, see below). For now, I just want to start a discussion by posting this to the rele