[MPlayer-dev-eng] [PATCH] Make stream support http redirect

Reimar Döffinger Reimar.Doeffinger at stud.uni-karlsruhe.de
Sun Nov 18 11:00:18 CET 2007


Hello,
On Sun, Nov 18, 2007 at 09:37:39AM +0800, Ulion wrote:
[...]
> Thank you, I missed one 'goto out', did not set the return value
> correctly. Here's the fixed patch, also deny redirect from http:// to
> file:// as a little security feature.

That is sometimes called "enumerating badness" and a true security
anti-pattern. If anything check for mms and explicitly allow redirect to
that and only that.

Greetings,
Reimar Döffinger



More information about the MPlayer-dev-eng mailing list