| Summary: | dev-libs/libburn - buffer overflow in libburn/write.c:1174 | ||
|---|---|---|---|
| Product: | Gentoo Linux | Reporter: | Richard Goedeken <richard42g> |
| Component: | [OLD] Library | Assignee: | Daniel Pielmeier <billie> |
| Status: | RESOLVED FIXED | ||
| Severity: | normal | CC: | media-optical |
| Priority: | Normal | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Package list: | Runtime testing required: | --- | |
|
Description
Richard Goedeken
2014-03-13 14:32:56 UTC
(In reply to Richard Goedeken from comment #0) > I burned about 10 coasters before I finally tracked down and fixed this bug > in libburn-1.3.4. It also happens in 1.3.2 and 1.3.6. It's not about 1.3.4 then. I have contacted the upstream developer and he confirmed the bug. I forward his comments here: ------------------------------------------------------------- The bug is confirmed and will be fixed soon. It happens only with CD TAO. So a workaround is to select write type "SAO". Thank you for finding this bug which was introduced by libburn-0.3.4 seven years ago. ------------------------------------------------------------- + 14 Mar 2014; Daniel Pielmeier <billie@gentoo.org> libburn-1.3.4.ebuild, + libburn-1.3.6.ebuild, +files/libburn-1.3.6-buffer-overflow.patch: + Add patch to prevent a buffer overflow in libburn/write.c which may occur for + certain tracks when trying to burn a CD in TAO mode. Thanks to Richard + Goedeken for the report (bug #504488) and proposed patch. Additional thanks + go to upstream author Thomas Schmitt for his quick response regarding the + issue. This is fixed in libburn-1.3.4 and libburn-1.3.6. Thanks again for the detailed bug report and the proposed solution. |