From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on dcvr.yhbt.net X-Spam-Level: X-Spam-ASN: AS3561 216.34.176.0/20 X-Spam-Status: No, score=-3.1 required=3.0 tests=AWL,BAYES_00,DKIM_SIGNED, HEADER_FROM_DIFFERENT_DOMAINS,RCVD_IN_DNSWL_HI,RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL,RP_MATCHES_RCVD,SPF_HELO_PASS,SPF_PASS,T_DKIM_INVALID shortcircuit=no autolearn=ham autolearn_force=no version=3.4.0 Received: from lists.sourceforge.net (lists.sourceforge.net [216.34.181.88]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dcvr.yhbt.net (Postfix) with ESMTPS id D68EF20A10 for ; Tue, 7 Nov 2017 17:54:54 +0000 (UTC) Received: from localhost ([127.0.0.1] helo=sfs-ml-1.v29.ch3.sourceforge.com) by sfs-ml-1.v29.ch3.sourceforge.com with esmtp (Exim 4.89) (envelope-from ) id 1eC85I-0005QP-G6; Tue, 07 Nov 2017 17:54:48 +0000 Received: from sfi-mx-4.v28.ch3.sourceforge.com ([172.29.28.194] helo=mx.sourceforge.net) by sfs-ml-1.v29.ch3.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.89) (envelope-from ) id 1eC85H-0005QI-64 for sox-devel@lists.sourceforge.net; Tue, 07 Nov 2017 17:54:47 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=In-Reply-To:Content-Transfer-Encoding:Content-Type: MIME-Version:References:Message-ID:Subject:Cc:To:From:Date:Sender:Reply-To: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=KrR4VTURFHtNThwX+EShio2f2aGKU+c2kpVLtFNqeMI=; b=XQu0sVCrTuk5xVHNTISLUBKbe7 3Du9h0150Zf6yetCo7necNZCDa323+6q2XLuCcz/1iO3zZjc28JZwZIRTN53uXwaMTKJB7HlnGJyk 17i9N8+iJ06/Q9HM37oBxY85daVl0/tuoXsMX3i4mWHAaOrXpi3KoGtSoVOi0S2K1h+Q=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=In-Reply-To:Content-Transfer-Encoding:Content-Type:MIME-Version: References:Message-ID:Subject:Cc:To:From:Date:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=KrR4VTURFHtNThwX+EShio2f2aGKU+c2kpVLtFNqeMI=; b=QwO7MtS6iNSpVaNUWa1hGLcSl+ YxZA/gDK7LmchKdTVjUmiTxYkUB6yJ3Fiq5uCWuoiR/qzo8MnP4vSQUoCXqXXLyX6CUMkePs2TXSy BcQxtEuu7+UQCPtdjwCqfpCK5MDFy3rh6bsPn4KgxT+ZjfMJcv7Rsg8Hi0SbnKIxRTRo=; Received: from dcvr.yhbt.net ([64.71.152.64]) by sfi-mx-4.v28.ch3.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.89) id 1eC85E-0002P8-Vq for sox-devel@lists.sourceforge.net; Tue, 07 Nov 2017 17:54:47 +0000 Received: from localhost (dcvr.yhbt.net [127.0.0.1]) by dcvr.yhbt.net (Postfix) with ESMTP id 2416420A10; Tue, 7 Nov 2017 17:54:39 +0000 (UTC) Date: Tue, 7 Nov 2017 17:54:39 +0000 From: Eric Wong To: =?utf-8?B?TcOlbnMgUnVsbGfDpXJk?= Message-ID: <20171107175438.GC13483@starla> References: <20171107011423.GA26133@starla> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: X-Headers-End: 1eC85E-0002P8-Vq Subject: Re: [PATCH] adpcm: fix stack overflow (CVE-2017-15372) X-BeenThere: sox-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: sox-devel@lists.sourceforge.net Cc: sox-devel@lists.sourceforge.net Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Errors-To: sox-devel-bounces@lists.sourceforge.net TcOlbnMgUnVsbGfDpXJkIDxtYW5zQG1hbnNyLmNvbT4gd3JvdGU6Cj4gVGhpcyB3aWxsIGxlYWsg bWVtb3J5IGxpa2UgY3JhenkuCgpZb3UncmUgcmlnaHQuIEkgc29tZWhvdyBnb3Qgc3BvaWxlZCBp bnRvIHRoaW5raW5nIGl0IHdhcwphbGxvY2EtbGlrZSBmcm9tIGFub3RoZXIgcHJvamVjdCA6eC4K Cj4gSSdkIHByZWZlciBub3QgdG8gZG8gYSBtYWxsb2MvZnJlZSBmb3IgZWFjaCBibG9jaywgYnV0 IHJhdGhlciBkbyBpdCBqdXN0Cj4gb25jZS4gIFRoaXMgd2lsbCByZXF1aXJlIGEgbGl0dGxlIG1v cmUgd29yaywgb2YgY291cnNlLgoKWWVzLCBpdCBzaG91bGQgYmUgaW4gdGhlIHBlci1zdHJlYW0g cHJpdmF0ZSBkYXRhLiAgV2lsbCB3b3JrIG9uCml0IGxhdGVyIHRvZGF5IGlmIHlvdSdyZSBidXN5 LgoKLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tCkNoZWNrIG91dCB0aGUgdmlicmFudCB0ZWNoIGNvbW11 bml0eSBvbiBvbmUgb2YgdGhlIHdvcmxkJ3MgbW9zdAplbmdhZ2luZyB0ZWNoIHNpdGVzLCBTbGFz aGRvdC5vcmchIGh0dHA6Ly9zZG0ubGluay9zbGFzaGRvdApfX19fX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fXwpTb1gtZGV2ZWwgbWFpbGluZyBsaXN0ClNvWC1kZXZl bEBsaXN0cy5zb3VyY2Vmb3JnZS5uZXQKaHR0cHM6Ly9saXN0cy5zb3VyY2Vmb3JnZS5uZXQvbGlz dHMvbGlzdGluZm8vc294LWRldmVsCg==