[FFmpeg-devel] [PATCHv3] On2 VP7 decoder

Vittorio Giovara vittorio.giovara at gmail.com
Thu Mar 27 19:17:49 CET 2014


On Thu, Mar 27, 2014 at 5:01 PM, compn <tempn at twmi.rr.com> wrote:
> On Thu, 27 Mar 2014 12:16:36 +0100
> Vittorio Giovara <vittorio.giovara at gmail.com> wrote:
>
>> On Thu, Mar 27, 2014 at 5:01 AM, Michael Niedermayer
>> <michaelni at gmx.at> wrote:
>> > On Wed, Mar 26, 2014 at 04:37:43AM +0100, Vittorio Giovara wrote:
>> >>
>> >> Furthermore it introduces at least a possible NULL pointer
>> >> dereferences in vp7_decode_frame_header() when prev_frame is NULL.
>> >
>> > fixed
>> >
>>
>> You're welcome, it would be just nice if these kind of security
>> reports were bi-derectional.
>> Cheers,
>
> what mailing list or email do you want michael to send security
> reports/patches to?

This is kinda off-topic, but I don't think the patches are useful as
the code between projects is quite different nowadays (and contrary to
popular belief this is actually a good thing).
I just asked for reports, but if anyone would like to send security
patches to Libav I can be put in --cc when they are sent for review
(because security patches are reviewed on the ML, aren't they?).
-- 
Vittorio


More information about the ffmpeg-devel mailing list