[FFmpeg-devel] [PATCH] avformat/hls: Check file extensions

wm4 nfxjfg at googlemail.com
Sat Jun 3 16:03:05 EEST 2017


On Sat, 3 Jun 2017 14:58:19 +0200
Michael Niedermayer <michael at niedermayer.cc> wrote:


> Do you object to fixing this security issue that has a working exploit?
> Can you provide a testcase the fix breaks ? So i can look into what
> can be done about it ? (multiple testcases would be even better so
> theres a lower chance of breaking things)

I haven't seen any proof that this is a real security issue yet.

It all seems to be based on a lot of assumptions, and always seems to
involve social engineering - basically making stupid people to stupid
things.


More information about the ffmpeg-devel mailing list