No description
Find a file
Michael Niedermayer e447d3143f avformat/hls: Check local file extensions
This reduces the attack surface of local file-system
information leaking.

It prevents the existing exploit leading to an information leak. As
well as similar hypothetical attacks.

Leaks of information from files and symlinks ending in common multimedia extensions
are still possible. But files with sensitive information like private keys and passwords
generally do not use common multimedia filename extensions.
It does not stop leaks via remote addresses in the LAN.

The existing exploit depends on a specific decoder as well.
It does appear though that the exploit should be possible with any decoder.
The problem is that as long as sensitive information gets into the decoder,
the output of the decoder becomes sensitive as well.
The only obvious solution is to prevent access to sensitive information. Or to
disable hls or possibly some of its feature. More complex solutions like
checking the path to limit access to only subdirectories of the hls path may
work as an alternative. But such solutions are fragile and tricky to implement
portably and would not stop every possible attack nor would they work with all
valid hls files.

Developers have expressed their dislike / objected to disabling hls by default as well
as disabling hls with local files. There also where objections against restricting
remote url file extensions. This here is a less robust but also lower
inconvenience solution.
It can be applied stand alone or together with other solutions.
limiting the check to local files was suggested by nevcairiel

This recommits the security fix without the author name joke which was
originally requested by Nicolas.

Found-by: Emil Lerner and Pavel Cheremushkin
Reported-by: Thierry Foucu <tfoucu@google.com>

Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 189ff42196)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
2017-06-05 23:16:54 +02:00
compat use a wrapper script to call MS link.exe to avoid mixing with /usr/bin/link.exe 2015-07-24 20:02:32 +02:00
doc doc/filters: Clarify scale2ref example 2017-06-05 23:16:54 +02:00
libavcodec avcodec/qdrw: Fix null pointer dereference 2017-06-05 23:16:54 +02:00
libavdevice avdevice/libdc1394: Make dc1394_frame_format and dc1394_frame_rate, static 2015-08-30 13:10:11 +02:00
libavfilter avfilter/vf_uspp: Fix currently unused input frame dimensions 2017-05-20 03:41:33 +02:00
libavformat avformat/hls: Check local file extensions 2017-06-05 23:16:54 +02:00
libavresample x86inc: Drop SECTION_TEXT macro 2015-08-04 20:13:09 +02:00
libavutil avutil/softfloat: Fix sign error in and improve documentation of av_int2sf() 2017-06-05 23:16:54 +02:00
libpostproc postproc: fix unaligned access 2016-02-23 18:01:08 +01:00
libswresample swresample/resample: free existing ResampleContext on reinit 2017-03-21 12:19:20 -03:00
libswscale libswscale/tests/swscale: Fix uninitialized variables 2017-05-20 03:41:33 +02:00
presets presets: remove moldering iPod presets 2014-06-17 16:15:04 -08:00
tests avcodec/vp56: Implement very basic error concealment 2017-05-20 03:41:32 +02:00
tools zmqsend: Initialize ret to 0 2016-12-06 00:59:22 +01:00
.gitattributes Treat all '*.pnm' files as non-text file 2014-11-28 17:52:43 -05:00
.gitignore doc/examples: rename avio_list_dir -> avio_dir_cmd 2015-08-16 02:16:47 +02:00
arch.mak use mmi instead of loongson3 as simd-optimization flag 2015-07-07 03:46:57 +02:00
Changelog Update for 2.8.11 2017-02-08 21:45:54 +01:00
cmdutils.c cmdutils: fix typos 2016-11-26 15:12:25 +01:00
cmdutils.h cmdutils: fix typos 2016-11-26 15:12:25 +01:00
cmdutils_common_opts.h opts: add list device sources/sinks options 2014-10-25 20:20:31 +02:00
cmdutils_opencl.c OpenCL: Avoid potential buffer overflow in cmdutils_opencl.c 2015-04-28 12:18:23 +02:00
common.mak Merge commit '3ae0e721c7' 2015-07-22 16:30:37 +02:00
configure configure: bump year 2017-02-08 21:17:51 +01:00
COPYING.GPLv2
COPYING.GPLv3
COPYING.LGPLv2.1
COPYING.LGPLv3
CREDITS
ffmpeg.c cmdutils: remove the current working directory from the DLL search path on win32 2016-08-15 20:25:13 +02:00
ffmpeg.h ffmpeg: switch swscale option handling to AVDictionary similar to what the other subsystems use 2015-08-08 14:44:15 +02:00
ffmpeg_dxva2.c ffmpeg_dxva2: call GetDesktopWindow() in place of GetShellWindow() 2015-06-03 16:25:08 +02:00
ffmpeg_filter.c lavfi: fix compilation with FF_API_OLD_FILTER_OPTS=0. 2015-08-18 22:22:49 -04:00
ffmpeg_opt.c Avoid using the term "file" and prefer "url" in some docs and comments 2016-12-06 00:59:22 +01:00
ffmpeg_vdpau.c ffmpeg_vdpau: Ignore decoder's max supported level 2015-08-16 15:02:33 -07:00
ffmpeg_videotoolbox.c avcodec: add new Videotoolbox hwaccel. 2015-08-03 10:12:10 +02:00
ffplay.c cmdutils: remove the current working directory from the DLL search path on win32 2016-08-15 20:25:13 +02:00
ffprobe.c cmdutils: remove the current working directory from the DLL search path on win32 2016-08-15 20:25:13 +02:00
ffserver.c ffserver: Check chunk size 2016-12-06 00:59:22 +01:00
ffserver_config.c ffserver: use -b instead of -ab for setting audio bitrate. 2015-08-28 14:59:58 -04:00
ffserver_config.h ffserver: Use singlejpeg muxer for jpeg 2015-06-08 03:36:22 +02:00
INSTALL.md
library.mak build: add LDLIBFLAGS 2015-07-08 14:35:02 +02:00
LICENSE.md avfilter/vf_removegrain: add x86 and x86_64 SSE2 functions 2015-07-14 23:50:50 +00:00
MAINTAINERS MAINTAINERs cleanup (remove myself from things i de facto dont maintain) 2016-08-15 18:54:34 +02:00
Makefile avcodec: add new Videotoolbox hwaccel. 2015-08-03 10:12:10 +02:00
README.md README: add ffserver 2015-02-12 11:59:22 +01:00
RELEASE Update for 2.8.11 2017-02-08 21:45:54 +01:00
RELEASE_NOTES RELEASE_NOTES based on 2.7 2015-09-08 22:33:04 +02:00
version.sh version.sh: Print versions based on the last git tag for release branches 2014-07-28 15:44:59 +02:00

FFmpeg README

FFmpeg is a collection of libraries and tools to process multimedia content such as audio, video, subtitles and related metadata.

Libraries

  • libavcodec provides implementation of a wider range of codecs.
  • libavformat implements streaming protocols, container formats and basic I/O access.
  • libavutil includes hashers, decompressors and miscellaneous utility functions.
  • libavfilter provides a mean to alter decoded Audio and Video through chain of filters.
  • libavdevice provides an abstraction to access capture and playback devices.
  • libswresample implements audio mixing and resampling routines.
  • libswscale implements color conversion and scaling routines.

Tools

  • ffmpeg is a command line toolbox to manipulate, convert and stream multimedia content.
  • ffplay is a minimalistic multimedia player.
  • ffprobe is a simple analysis tool to inspect multimedia content.
  • ffserver is a multimedia streaming server for live broadcasts.
  • Additional small tools such as aviocat, ismindex and qt-faststart.

Documentation

The offline documentation is available in the doc/ directory.

The online documentation is available in the main website and in the wiki.

Examples

Coding examples are available in the doc/examples directory.

License

FFmpeg codebase is mainly LGPL-licensed with optional components licensed under GPL. Please refer to the LICENSE file for detailed information.