Bug#509616: [gmane.comp.video.ffmpeg.devel] [PATCH] fix crash in vp3.c

2008-12-28 Thread Reinhard Tartler
Nico Golde writes: >> of course, if there is a bug in ffmpeg, it of course should be >> fixed. AFAIU Michael's response he acknowledges that there is a bug in >> the function. However ffmpeg (and debian as well, btw) has a history of >> fixing the bugs only with sensible fixes, which involves und

Bug#509616: [gmane.comp.video.ffmpeg.devel] [PATCH] fix crash in vp3.c

2008-12-28 Thread Nico Golde
Hi, * Reinhard Tartler [2008-12-28 12:37]: > Nico Golde writes: > >> I have to admit that I don't really understand as well what the code > >> here does, but I agree to michael that the approach to this patch is > >> wrong. FFmpeg cannot be made robust to all kind of wrong data. There > >> will a

Bug#509616: [gmane.comp.video.ffmpeg.devel] [PATCH] fix crash in vp3.c

2008-12-28 Thread Reinhard Tartler
Nico Golde writes: >> I have to admit that I don't really understand as well what the code >> here does, but I agree to michael that the approach to this patch is >> wrong. FFmpeg cannot be made robust to all kind of wrong data. There >> will always be some ways how to abuse a library. > > Why? I