gopxl / beep

A little package that brings sound to any Go application. Suitable for playback and audio-processing.
MIT License
248 stars 9 forks source link

Out-of-bounds bug affecting faiface/beep and gopxl/beep #158

Open enn-msi opened 4 months ago

enn-msi commented 4 months ago

Hi beep maintainers,

The company I work for utilizes the gopxl/beep package in one of our products, and we discovered an out-of-bounds read bug affecting both gopxl/beep and faiface/beep.

I would like to report this issue privately and follow responsible disclosure best practices, as it can pose a security vulnerability (Denial of Service) in scenarios where the functionality affected by the bug processes untrusted data. However, there is no security.md policy file in this repository, and I've got no reply to the emails I've sent to the maintainers/contributors (i.e., the ones I could find an email).

Could one of the project maintainers reach out to me or add the security.md policy file so I could report through Github, please?

Thanks

dusk125 commented 4 months ago

@enn-msi please join the gopxl discord and we'll get a private channel setup for the disclosure. Thanks