Skip to content
Snippets Groups Projects
  1. Jan 08, 2017
    • Tobias Stoeckmann's avatar
      ffserver: local OOB write with custom program name · 95d9a85c
      Tobias Stoeckmann authored
      
      When the command line for children is created, it is assumed that
      my_program_name always ends with "ffserver", which doesn't have to
      be true if ffserver is called through a symbolic link.
      
      In such a case, it could be that not enough space for "ffmpeg" is
      available at the end, leading to a buffer overflow.
      
      One example would be:
      
      $ ln -s /usr/bin/ffserver ~/f; ~/f
      
      As this is only a local buffer overflow, i.e. is based on a weird
      program call, this has NO security impact.
      
      Signed-off-by: default avatarMichael Niedermayer <michael@niedermayer.cc>
      95d9a85c
  2. Dec 05, 2016
  3. Dec 03, 2016
  4. Dec 01, 2016
  5. Nov 30, 2016
  6. Nov 29, 2016
  7. Nov 28, 2016
  8. Nov 27, 2016
  9. Nov 08, 2016
  10. Nov 07, 2016
  11. Aug 08, 2016
  12. May 26, 2016
  13. Mar 08, 2016
  14. Feb 21, 2016
    • Oliver Collyer's avatar
      ffserver&ffm: Fixed issues preventing ffserver write_index and files_size from... · a2f8beef
      Oliver Collyer authored
      ffserver&ffm: Fixed issues preventing ffserver write_index and files_size from being set correctly which was breaking ffserver streaming.
      
      I discovered that ffserver streaming was broken (it seems like it has been since 20th November) and I opened a ticket for this (https://trac.ffmpeg.org/ticket/5250 <https://trac.ffmpeg.org/ticket/5250
      
      >).
      
      I spent yesterday learning git bisect (with the kind help of cehoyos) to painstakingly track down the cause. This was made more difficult due to the presence of a segfault in ffserver during the period where the bug was introduced so I first had to identify when and how that was fixed and then retrospectively apply that fix again for each step of the second git bisect to find the actual bug.
      
      Anyway, the fruits of my labour are the innocent looking patch below to correct a couple of typos and define a valid range for two variables.
      
      Signed-off-by: default avatarMichael Niedermayer <michael@niedermayer.cc>
      a2f8beef
  15. Dec 29, 2015
  16. Dec 27, 2015
  17. Dec 19, 2015
  18. Dec 15, 2015
Loading