‹ BackHN Continuity

Thread

Memory-Safe WebP Decoding

69 points · 28 comments · computerbuster

  1. jessa0 · · focus · HN ↗
    Related is Signal Messenger's webpsan crate, which validates webp container syntax before it is passed to libwebp. It stops just short of decoding actual pixel data, however, as the way webp works requires the entire canvas to be allocated in order to fully decode pixel data, which would have just made webpsan a full-on decoder anyway..

    <a href="https:&#x2F;&#x2F;docs.rs&#x2F;webpsan&#x2F;latest&#x2F;webpsan&#x2F;" rel="nofollow">https:&#x2F;&#x2F;docs.rs&#x2F;webpsan&#x2F;latest&#x2F;webpsan&#x2F;

    1. computerbuster · · focus · HN ↗
      Nice, I didn&#x27;t know about this!
    2. thereisno · · focus · HN ↗
      Validators separate from parsers have led to many vulnerabilities in the past. There&#x27;s always something the validator didn&#x27;t catch that crashed the parser anyway.
      1. nine_k · · focus · HN ↗
        A validator before an unsafe parser is strictly better than just the unsafe parser, but worse than a safe parser.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.