[FFmpeg-devel] [PATCH 2/2] avformat: add protocol_whitelist

Nicolas George george at nsup.org
Sun Jan 24 20:20:41 CET 2016


Le quintidi 5 pluviôse, an CCXXIV, Andreas Cadhalpun a écrit :
> The idea is to classify protocols as local (file, concat) or remote (http, tcp).

I am sorry, but this is completely broken. First, concat is not local.
Second, local/remote is not a relevant distinction for security.

Any design made with these assumptions at its code would be insecure.

Regards,

-- 
  Nicolas George
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: Digital signature
URL: <http://ffmpeg.org/pipermail/ffmpeg-devel/attachments/20160124/c8783ab8/attachment.sig>


More information about the ffmpeg-devel mailing list