<p dir="ltr"><br>
Le 18 nov. 2014 06:30, "Ondřej Surý" <<a href="mailto:ondrej@sury.org">ondrej@sury.org</a>> a écrit :<br>
><br>
> Bastien,<br>
><br>
> don't get me wrong. I think this is "serious" bug, but not with severity<br>
> "serious"[1] as this needs the user to do an explicit operation to<br>
> trigger the bug.</p>
<p dir="ltr">It could be trigerred by imagick remotly.</p>
<p dir="ltr">Bastien<br>
><br>
> 1. see <a href="https://www.debian.org/Bugs/Developer#severities">https://www.debian.org/Bugs/Developer#severities</a>:<br>
><br>
> Cheers,<br>
> Ondrej<br>
><br>
> On Mon, Nov 17, 2014, at 21:21, Bastien ROUCARIES wrote:<br>
> > Hi,<br>
> ><br>
> > For me it is a serious bug.<br>
> ><br>
> > According to <a href="http://sourceforge.net/p/libjpeg-turbo/bugs/64/?page=1">http://sourceforge.net/p/libjpeg-turbo/bugs/64/?page=1</a><br>
> > (see <a href="http://sourceforge.net/p/libjpeg-turbo/bugs/64/?page=1">http://sourceforge.net/p/libjpeg-turbo/bugs/64/?page=1</a>):<br>
> ><br>
> > >Even though I'm doing the most I can to stack the deck in favor of the bug, it still only occurs once in about every 25 million iterations.<br>
> > >I have checked in your patch without modifications.<br>
> > ><br>
> > >So far, 130 bytes is the maximum I have been able to produce for a single MCU using the test, after literally a billion iterations. However, I am running it overnight so I can collect as many cases of >degenerate input images as I can, so I can hopefully determine what the upper bound is for the local buffer.<br>
> ><br>
> > Thus I am tented to add it is a true bug.<br>
> ><br>
> > Bastien<br>
><br>
><br>
> --<br>
> Ondřej Surý <<a href="mailto:ondrej@sury.org">ondrej@sury.org</a>><br>
> Knot DNS (<a href="https://www.knot-dns.cz/">https://www.knot-dns.cz/</a>) – a high-performance DNS server<br>
</p>