diff options
author | Maxim Andreev <andreevmaxim@gmail.com> | 2016-01-13 11:51:12 +0300 |
---|---|---|
committer | Michael Niedermayer <michael@niedermayer.cc> | 2016-01-15 17:23:55 +0100 |
commit | 8b93f6676b89d23bc5f6e0f4e0afac469de881b9 (patch) | |
tree | c0df68e132ca28f0f03e077d9e7f6d373ded1d61 | |
parent | 6d5fca34a629daaa1941942130961ffa08bf56a1 (diff) | |
download | ffmpeg-8b93f6676b89d23bc5f6e0f4e0afac469de881b9.tar.gz |
avformat/hls: forbid all protocols except http(s) & file
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 7145e80b4f78cff5ed5fee04d4c4d53daaa0e077)
Conflicts:
libavformat/hls.c
-rw-r--r-- | libavformat/hls.c | 11 |
1 files changed, 11 insertions, 0 deletions
diff --git a/libavformat/hls.c b/libavformat/hls.c index af890bd4ad..96bcb365ed 100644 --- a/libavformat/hls.c +++ b/libavformat/hls.c @@ -938,6 +938,12 @@ static int open_input(HLSContext *c, struct playlist *pls) seg->url, seg->url_offset, pls->index); if (seg->key_type == KEY_NONE) { + const char *proto_name = avio_find_protocol_name(seg->url); + if (!av_strstart(proto_name, "http", NULL) && !av_strstart(proto_name, "file", NULL)) { + ret = AVERROR_INVALIDDATA; + goto cleanup; + } + ret = ffurl_open(&pls->input, seg->url, AVIO_FLAG_READ, &pls->parent->interrupt_callback, &opts); @@ -945,6 +951,11 @@ static int open_input(HLSContext *c, struct playlist *pls) char iv[33], key[33], url[MAX_URL_SIZE]; if (strcmp(seg->key, pls->key_url)) { URLContext *uc; + const char *proto_name = avio_find_protocol_name(seg->key); + if (!av_strstart(proto_name, "http", NULL) && !av_strstart(proto_name, "file", NULL)) { + ret = AVERROR_INVALIDDATA; + goto cleanup; + } if (ffurl_open(&uc, seg->key, AVIO_FLAG_READ, &pls->parent->interrupt_callback, &opts2) == 0) { if (ffurl_read_complete(uc, pls->key, sizeof(pls->key)) |