No description
Find a file
Michael Niedermayer 345202af04
avformat/hls: Be more picky on extensions
This blocks disallowed extensions from probing
It also requires all available segments to have matching extensions to the format
mpegts is treated independent of the extension

It is recommended to set the whitelists correctly
instead of depending on extensions, but this should help a bit,
and this is easier to backport

Fixes: CVE-2023-6602 II. HLS Force TTY Demuxer
Fixes: CVE-2023-6602 IV. HLS XBIN Demuxer DoS Amplification

The other parts of CVE-2023-6602 have been fixed by prior commits

Found-by: Harvey Phillips of Amazon Element55 (element55)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 91d96dc8dd)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
2025-03-16 22:12:25 +01:00
compat compat/cuda: correct ushort4 to use ushort 2021-02-22 17:03:52 +01:00
doc avformat/hls: Be more picky on extensions 2025-03-16 22:12:25 +01:00
ffbuild ffbuild: Avoid using the --preprocessor argument to windres 2021-06-24 23:25:30 +03:00
fftools fftools/ffmpeg: Check read() for failure 2024-07-21 18:55:35 +02:00
libavcodec avcodec/h263dec: Check against previous dimensions instead of coded 2025-03-16 22:12:23 +01:00
libavdevice configure: improve check for POSIX ioctl 2024-09-01 19:57:19 -04:00
libavfilter avfilter/bwdif: account for chroma sub-sampling in min size calculation 2025-03-16 22:12:25 +01:00
libavformat avformat/hls: Be more picky on extensions 2025-03-16 22:12:25 +01:00
libavresample avresample: remove deprecated attribute from the AVAudioResampleContext struct 2018-01-09 10:56:53 -03:00
libavutil avutil/avstring: dont mess with NULL pointers in av_match_list() 2025-03-16 22:12:20 +01:00
libpostproc Bump Versions before release/4.4 branch 2021-03-20 01:01:12 +01:00
libswresample libswresample/audioconvert: Fix undefined NULL + 0 2021-04-02 21:39:54 +02:00
libswscale swscale/output: Fix undefined overflow in yuv2rgba64_full_X_c_template() 2025-03-16 22:12:18 +01:00
presets
tests fate/subtitles: Ignore line endings for sub-scc test 2024-04-14 03:25:00 +02:00
tools tools/coverity: Phase 1 study of anti-halicogenic for coverity av_rescale() 2024-07-21 20:02:27 +02:00
.gitattributes fate: add SCC test 2017-01-27 17:06:42 +01:00
.gitignore tools/python: add script to convert TensorFlow model (.pb) to native model (.model) 2019-07-01 10:23:47 -03:00
.mailmap mailmap: add entry for myself 2021-03-09 02:09:55 +00:00
.travis.yml Merge commit '899ee03088' 2019-03-14 15:53:16 -03:00
Changelog Update for 4.4.5 2024-07-28 22:38:33 +02:00
configure lsws/ppc/yuv2rgb_altivec: Fix build in non-VSX environments with Clang v2 2025-03-16 00:48:16 -04:00
CONTRIBUTING.md
COPYING.GPLv2
COPYING.GPLv3
COPYING.LGPLv2.1
COPYING.LGPLv3
CREDITS Use https for repository links 2023-04-07 23:40:46 +02:00
INSTALL.md INSTALL: explain the circular dependency issue and solution 2025-03-16 22:12:11 +01:00
LICENSE.md avfilter/vf_geq: Relicense to LGPL 2019-12-28 11:20:48 +01:00
MAINTAINERS MAINTAINERS: Update the entries for the release maintainer for FFmpeg 2024-07-21 17:20:27 +02:00
Makefile avcodec: move core AVCodecContext functions from util.c to a new file 2021-03-19 15:35:35 -03:00
README.md Remove the ffserver program 2018-01-06 18:31:37 +00:00
RELEASE Update for 4.4.5 2024-07-28 22:38:33 +02:00
RELEASE_NOTES Update missed irc links 2021-06-18 20:53:56 +02:00

FFmpeg README

FFmpeg is a collection of libraries and tools to process multimedia content such as audio, video, subtitles and related metadata.

Libraries

  • libavcodec provides implementation of a wider range of codecs.
  • libavformat implements streaming protocols, container formats and basic I/O access.
  • libavutil includes hashers, decompressors and miscellaneous utility functions.
  • libavfilter provides a mean to alter decoded Audio and Video through chain of filters.
  • libavdevice provides an abstraction to access capture and playback devices.
  • libswresample implements audio mixing and resampling routines.
  • libswscale implements color conversion and scaling routines.

Tools

  • ffmpeg is a command line toolbox to manipulate, convert and stream multimedia content.
  • ffplay is a minimalistic multimedia player.
  • ffprobe is a simple analysis tool to inspect multimedia content.
  • Additional small tools such as aviocat, ismindex and qt-faststart.

Documentation

The offline documentation is available in the doc/ directory.

The online documentation is available in the main website and in the wiki.

Examples

Coding examples are available in the doc/examples directory.

License

FFmpeg codebase is mainly LGPL-licensed with optional components licensed under GPL. Please refer to the LICENSE file for detailed information.

Contributing

Patches should be submitted to the ffmpeg-devel mailing list using git format-patch or git send-email. Github pull requests should be avoided because they are not part of our review process and will be ignored.