[FFmpeg-devel] [PATCH] avformat/hls: Fix DoS due to infinite loop

wm4 nfxjfg at googlemail.com
Tue Aug 29 11:59:47 EEST 2017


On Tue, 29 Aug 2017 03:07:45 +0200
Michael Niedermayer <michael at niedermayer.cc> wrote:

> On Mon, Aug 28, 2017 at 11:21:39AM +0200, wm4 wrote:
> > On Sun, 27 Aug 2017 19:16:03 +0200
> > Michael Niedermayer <michael at niedermayer.cc> wrote:
> >   
> > > On Sat, Aug 26, 2017 at 01:26:58AM +0200, Michael Niedermayer wrote:  
> > > > Fixes: loop.m3u
> > > > 
> > > > The default max iteration count of 1000 is arbitrary and ideas for a better solution are welcome
> > > > 
> > > > Found-by: Xiaohei and Wangchu from Alibaba Security Team
> > > > Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
> > > > ---
> > > >  doc/demuxers.texi | 18 ++++++++++++++++++
> > > >  libavformat/hls.c |  7 +++++++
> > > >  2 files changed, 25 insertions(+)    
> > > 
> > > applied
> > > 
> > > [...]  
> > 
> > I rejected this approach, but I guess patch reviews are ignored anyway.  
> 
> I explicitly asked if you veto this patch, you did not veto it.
> It is extreemly inpolite, to ignore an explicit question about
> you objecting and afterwards claim your rejection was ignored.

I don't think a patch comment needs to be honored only if it was done
as an explicit veto. I didn't understand it this way either.


More information about the ffmpeg-devel mailing list