[FFmpeg-devel] [PATCH] fixed printf injection bug in mmsh requests

Michael Niedermayer michaelni at gmx.at
Wed Jun 15 19:20:22 CEST 2011

On Wed, Jun 15, 2011 at 09:06:27AM -0400, Kirill Zorin wrote:
> Looks like URL-encoded entities (e.g. %20) in mmsh:// input URLs get
> interpreted as format specifiers by ff_url_join, since the request
> path was provided to it as the format string.
> Let me know if anything's missing.


Michael     GnuPG fingerprint: 9FF2128B147EF6730BADF133611EC787040B0FAB

When the tyrant has disposed of foreign enemies by conquest or treaty, and
there is nothing more to fear from them, then he is always stirring up
some war or other, in order that the people may require a leader. -- Plato
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: Digital signature
URL: <http://ffmpeg.org/pipermail/ffmpeg-devel/attachments/20110615/4adf42c6/attachment.asc>

More information about the ffmpeg-devel mailing list