aboutsummaryrefslogtreecommitdiffstats
path: root/doc/APIchanges
diff options
context:
space:
mode:
authorMichael Niedermayer <michael@niedermayer.cc>2025-01-16 01:28:46 +0100
committerMichael Niedermayer <michael@niedermayer.cc>2025-01-26 01:12:28 +0100
commit91d96dc8ddaebe0b6cb393f672085e6bfaf15a31 (patch)
treece34f37ec0e8950347b882129098f7bd604f35c8 /doc/APIchanges
parentc733e2b5ed9cb78de731b1983ff867155862def9 (diff)
downloadffmpeg-91d96dc8ddaebe0b6cb393f672085e6bfaf15a31.tar.gz
avformat/hls: Be more picky on extensions
This blocks disallowed extensions from probing It also requires all available segments to have matching extensions to the format mpegts is treated independent of the extension It is recommended to set the whitelists correctly instead of depending on extensions, but this should help a bit, and this is easier to backport Fixes: CVE-2023-6602 II. HLS Force TTY Demuxer Fixes: CVE-2023-6602 IV. HLS XBIN Demuxer DoS Amplification The other parts of CVE-2023-6602 have been fixed by prior commits Found-by: Harvey Phillips of Amazon Element55 (element55) Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
Diffstat (limited to 'doc/APIchanges')
0 files changed, 0 insertions, 0 deletions