Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-06-01 Thread Michael Niedermayer
On Thu, Jun 01, 2017 at 12:13:35PM +0200, Michael Niedermayer wrote: > On Thu, Jun 01, 2017 at 11:02:09AM +0200, Tobias Rapp wrote: > > On 31.05.2017 18:33, Michael Niedermayer wrote: > > >On Wed, May 31, 2017 at 05:18:57PM +0200, Tobias Rapp wrote: > > >>On 31.05.2017 15:42, wm4 wrote: > > >>>On W

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-06-01 Thread Michael Niedermayer
On Thu, Jun 01, 2017 at 11:02:09AM +0200, Tobias Rapp wrote: > On 31.05.2017 18:33, Michael Niedermayer wrote: > >On Wed, May 31, 2017 at 05:18:57PM +0200, Tobias Rapp wrote: > >>On 31.05.2017 15:42, wm4 wrote: > >>>On Wed, 31 May 2017 14:49:19 +0200 > >>>Michael Niedermayer wrote: > >>> > [..

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-06-01 Thread Tobias Rapp
On 31.05.2017 18:33, Michael Niedermayer wrote: On Wed, May 31, 2017 at 05:18:57PM +0200, Tobias Rapp wrote: On 31.05.2017 15:42, wm4 wrote: On Wed, 31 May 2017 14:49:19 +0200 Michael Niedermayer wrote: [...] Security fixes should be as simple as possible. Well, your fix isn't simple. I

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-31 Thread Michael Niedermayer
On Wed, May 31, 2017 at 05:18:57PM +0200, Tobias Rapp wrote: > On 31.05.2017 15:42, wm4 wrote: > >On Wed, 31 May 2017 14:49:19 +0200 > >Michael Niedermayer wrote: > > > >> [...] > >> > >>Security fixes should be as simple as > >> possible. > > > >Well, your fix isn't simple. It adds yet another

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-31 Thread Michael Niedermayer
On Wed, May 31, 2017 at 03:42:41PM +0200, wm4 wrote: > On Wed, 31 May 2017 14:49:19 +0200 > Michael Niedermayer wrote: > > > On Wed, May 31, 2017 at 01:13:50PM +0200, wm4 wrote: > > > On Wed, 31 May 2017 12:51:35 +0200 > > > Michael Niedermayer wrote: > > > > > > > On Wed, May 31, 2017 at 11:

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-31 Thread Tobias Rapp
On 31.05.2017 15:42, wm4 wrote: On Wed, 31 May 2017 14:49:19 +0200 Michael Niedermayer wrote: >> [...] >> Security fixes should be as simple as possible. Well, your fix isn't simple. It adds yet another exception with questionable effect. It makes it more complex and harder to predict wh

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-31 Thread wm4
On Wed, 31 May 2017 14:49:19 +0200 Michael Niedermayer wrote: > On Wed, May 31, 2017 at 01:13:50PM +0200, wm4 wrote: > > On Wed, 31 May 2017 12:51:35 +0200 > > Michael Niedermayer wrote: > > > > > On Wed, May 31, 2017 at 11:52:06AM +0200, wm4 wrote: > > > > On Wed, 31 May 2017 11:29:56 +020

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-31 Thread Michael Niedermayer
On Wed, May 31, 2017 at 01:13:50PM +0200, wm4 wrote: > On Wed, 31 May 2017 12:51:35 +0200 > Michael Niedermayer wrote: > > > On Wed, May 31, 2017 at 11:52:06AM +0200, wm4 wrote: > > > On Wed, 31 May 2017 11:29:56 +0200 > > > Michael Niedermayer wrote: > > > > > > > On Wed, May 31, 2017 at 09:

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-31 Thread wm4
On Wed, 31 May 2017 12:51:35 +0200 Michael Niedermayer wrote: > On Wed, May 31, 2017 at 11:52:06AM +0200, wm4 wrote: > > On Wed, 31 May 2017 11:29:56 +0200 > > Michael Niedermayer wrote: > > > > > On Wed, May 31, 2017 at 09:03:34AM +0200, Hendrik Leppkes wrote: > > > > On Wed, May 31, 2017

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-31 Thread Michael Niedermayer
On Wed, May 31, 2017 at 11:52:06AM +0200, wm4 wrote: > On Wed, 31 May 2017 11:29:56 +0200 > Michael Niedermayer wrote: > > > On Wed, May 31, 2017 at 09:03:34AM +0200, Hendrik Leppkes wrote: > > > On Wed, May 31, 2017 at 2:09 AM, Michael Niedermayer > > > wrote: > > > > On Wed, May 31, 2017 at

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-31 Thread wm4
On Wed, 31 May 2017 11:29:56 +0200 Michael Niedermayer wrote: > On Wed, May 31, 2017 at 09:03:34AM +0200, Hendrik Leppkes wrote: > > On Wed, May 31, 2017 at 2:09 AM, Michael Niedermayer > > wrote: > > > On Wed, May 31, 2017 at 01:14:58AM +0200, Hendrik Leppkes wrote: > > >> On Wed, May 31, 2

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-31 Thread Michael Niedermayer
On Wed, May 31, 2017 at 09:03:34AM +0200, Hendrik Leppkes wrote: > On Wed, May 31, 2017 at 2:09 AM, Michael Niedermayer > wrote: > > On Wed, May 31, 2017 at 01:14:58AM +0200, Hendrik Leppkes wrote: > >> On Wed, May 31, 2017 at 12:52 AM, Michael Niedermayer > >> wrote: > >> > This prevents an expl

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-31 Thread Hendrik Leppkes
On Wed, May 31, 2017 at 2:09 AM, Michael Niedermayer wrote: > On Wed, May 31, 2017 at 01:14:58AM +0200, Hendrik Leppkes wrote: >> On Wed, May 31, 2017 at 12:52 AM, Michael Niedermayer >> wrote: >> > This prevents an exploit leading to an information leak >> > >> > The existing exploit depends on

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-30 Thread Michael Niedermayer
On Wed, May 31, 2017 at 01:14:58AM +0200, Hendrik Leppkes wrote: > On Wed, May 31, 2017 at 12:52 AM, Michael Niedermayer > wrote: > > This prevents an exploit leading to an information leak > > > > The existing exploit depends on a specific decoder as well. > > It does appear though that the explo

Re: [FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-30 Thread Hendrik Leppkes
On Wed, May 31, 2017 at 12:52 AM, Michael Niedermayer wrote: > This prevents an exploit leading to an information leak > > The existing exploit depends on a specific decoder as well. > It does appear though that the exploit should be possible with any decoder. > The problem is that as long as sens

[FFmpeg-devel] [PATCH] avformat/hls: Disallow local file access by default

2017-05-30 Thread Michael Niedermayer
This prevents an exploit leading to an information leak The existing exploit depends on a specific decoder as well. It does appear though that the exploit should be possible with any decoder. The problem is that as long as sensitive information gets into the decoder, the output of the decoder beco