Closed Bug 1561256 Opened 5 years ago Closed 5 years ago

Disable CRC checks in ogg framing for FUZZING

Categories

(Core :: Audio/Video: Playback, enhancement, P3)

Unspecified
Linux
enhancement

Tracking

()

RESOLVED FIXED
mozilla70
Tracking Status
firefox-esr60 --- wontfix
firefox-esr68 --- wontfix
firefox68 --- wontfix
firefox69 --- wontfix
firefox70 --- fixed

People

(Reporter: decoder, Assigned: decoder)

References

Details

(Keywords: sec-other, sec-want, Whiteboard: [post-critsmash-triage][adv-main70-])

Attachments

(1 file)

OGG Framing code has some CRC checks that we should probably disable in FUZZING builds.

FWIW Tristan added support upstream here: https://git.xiph.org/?p=ogg.git;a=commit;h=862163e51f87fa5bf57b437dd502052da597c723

Tristan are there any plans to roll out an OGG release any time in the near future?

Flags: needinfo?(le.businessman)

In that case, we should probably at least import the upstream patch rather than doing this on our own. We can stop using the patch once we import a new release that supports it (I wouldn't want to import a new release just for that).

(In reply to Tyson Smith [:tsmith] from comment #2)

FWIW Tristan added support upstream here: https://git.xiph.org/?p=ogg.git;a=commit;h=862163e51f87fa5bf57b437dd502052da597c723

Tristan are there any plans to roll out an OGG release any time in the near future?

The last release was 1.3.3 from November 2017, so I will check with some other xiph folks if it makes sense to do one now.

Flags: needinfo?(le.businessman)

I think we can still go ahead and land this patch and simply remove it if we decide to import the newer OGG release. I'll land this as soon as I can open up the bugs.

Flags: qe-verify-
Whiteboard: [post-critsmash-triage]

Just a head up, the latest Ogg release (with --disable-crc) has been published:
https://ftp.osuosl.org/pub/xiph/releases/ogg/libogg-1.3.4.tar.gz

Whiteboard: [post-critsmash-triage] → [post-critsmash-triage][adv-main70-]
Group: core-security-release
See Also: → 1857843
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: