[MPlayer-cvslog] r35988 - trunk/stream/http.c

Reimar Döffinger Reimar.Doeffinger at gmx.de
Sun Mar 17 11:58:41 CET 2013


On Sun, Mar 17, 2013 at 11:50:41AM +0100, reimar wrote:
> Author: reimar
> Date: Sun Mar 17 11:50:41 2013
> New Revision: 35988
> 
> Log:
> Handle the severely broken headers QuickTime Streaming Server sends.
> 
> Instead of ending the header with \r\n\r\n it ends with
> \r\n<4 byte MP3 header>\r\n.
> And programs like wget just silently accept this without even
> printing a warning!!

I have no idea what kind of shitty quality control one must have
that this kind of thing just slips by.
This kind of thing almost tempts me to put a black hat on, because
I'd be deeply surprised if the code wasn't shitty enough to expose
a couple of trivially exploitable bugs.
But it's just some random .edu server so probably nobody cares how
many holes it has anyway (or otherwise they'd at least update it...).


More information about the MPlayer-cvslog mailing list