libgme/game-music-emu

Out of bounds memory reads/writes in SNES/SPC module

Closed this issue · 4 comments

Original report by Sebastian Dröge (Bitbucket: [Sebastian Dröge](https://bitbucket.org/Sebastian Dröge), ).


https://scarybeastsecurity.blogspot.gr/2016/12/redux-compromising-linux-using-snes.html

At the very bottom, he also provides a patch.

Original comment by Michael Pyne (Bitbucket: mpyne, GitHub: mpyne).


Testing the patch now, seems to work fine. I guess this is as good a time as any to release 0.6.1...

Original comment by Michael Pyne (Bitbucket: mpyne, GitHub: mpyne).


Should now be resolved with commit d48c1c8

I have tagged it as 0.6.1 and will prepare a tarball for release. I have tested 0.6.1 with my local gstreamer installation and verified that it still seems to work, but I have not engaged in testing that is any more involved than that.

Original comment by Sebastian Dröge (Bitbucket: [Sebastian Dröge](https://bitbucket.org/Sebastian Dröge), ).


A new release would definitely be great to have, thanks! Also thanks for merging this so fast :)

Original comment by Michael Pyne (Bitbucket: mpyne, GitHub: mpyne).


In case you haven't seen it the 0.6.1 release is available on the Downloads page and is referenced on this repo's Wiki as well. I don't exactly have a mailing list going otherwise I'd announce it there too.