title
Products            Buy            Support Forum            Professional            About            Codec Central
 

FLAC 1.2.1 security release missing

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • SSD

    • Jan 2008
    • 1

    FLAC 1.2.1 security release missing

    FLAC 1.2.1 was released in September of last year. It has security fixes against buffer overflow attacks, ie. it fixes some security vulnerabilities. See:
    A free, open source codec for lossless audio compression and decompression


    The latest FLAC release in the CODEC central is 1.2.0, which is insecure (and old).

    Could there please be a new release of FLAC on CODEC central very soon? It's high time.

    (I know that the buffer overflows will not be remotely exploitable, as I'm not running a network service/server using them. But still, on general principle, it's not the right thing to have old software installed with known vulnerabilities. It doesn't feel right.)

    TIA,
    SSD
  • Spoon
    Administrator
    • Apr 2002
    • 44574

    #2
    Re: FLAC 1.2.1 security release missing

    It has been in beta for 2 months, see the beta section of the fourm. IMHO releasing programs without testing is more damaging.
    Spoon
    www.dbpoweramp.com

    Comment

    Working...

    ]]>