[MPlayer-users] The djb bughunt

Cs. Henk csaba-ml at beastie.creo.hu
Fri Dec 24 11:39:58 CET 2004


Hi!

Djb had a Unix security course in this semester
(http://cr.yp.to/2004-494.html). For completing the course, students had
to find security holes in existing Unix sotfware. One of them, Ariel
Berkman, found a hole in mplayer. It's all described here:

http://tigger.uic.edu/~jlongs2/holes/mplayer.txt

though the "proof of concept" code is not included.

The above doc seems to be a mail sent to this list, however, I couldn't
find it in the archives (and no previous mention of this bug, at least,
searching for djb or bernstein gave nothing). I suppose djb is not
subscribed to this list, and thus his mail was dropped.

Csaba




More information about the MPlayer-users mailing list