No description
Find a file
Michael Niedermayer 91d96dc8dd
avformat/hls: Be more picky on extensions
This blocks disallowed extensions from probing
It also requires all available segments to have matching extensions to the format
mpegts is treated independent of the extension

It is recommended to set the whitelists correctly
instead of depending on extensions, but this should help a bit,
and this is easier to backport

Fixes: CVE-2023-6602 II. HLS Force TTY Demuxer
Fixes: CVE-2023-6602 IV. HLS XBIN Demuxer DoS Amplification

The other parts of CVE-2023-6602 have been fixed by prior commits

Found-by: Harvey Phillips of Amazon Element55 (element55)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
2025-01-26 01:12:28 +01:00
compat compat/w32pthreads: change pthread_t into pointer to malloced struct 2024-12-16 09:43:19 +01:00
doc avformat/hls: Be more picky on extensions 2025-01-26 01:12:28 +01:00
ffbuild ffbuild/bin2c: misc fix 2025-01-13 23:58:36 +08:00
fftools fftools/ffprobe: print lossless frame flag 2025-01-05 22:23:16 +01:00
libavcodec avcodec/sanm: codec37 buffers are private 2025-01-26 01:10:52 +01:00
libavdevice avdevice/dshow: fix unused variable warning 2024-10-17 13:04:17 +02:00
libavfilter avfilter/vf_v360: Fix NULL pointer use 2025-01-15 01:27:46 +01:00
libavformat avformat/hls: Be more picky on extensions 2025-01-26 01:12:28 +01:00
libavutil libavutil/pixfmt: 16bit float support 2025-01-21 21:06:12 +01:00
libpostproc */version.h: bump after release/7.1 branch 2024-09-24 17:10:35 +02:00
libswresample arm: Consistently use proper interworking function returns 2024-10-09 15:52:51 +03:00
libswscale swscale/swscale: don't reject scaling when color parameters are not supported but conversion is not required 2025-01-22 12:15:18 -03:00
presets
tests libavutil/pixfmt: 16bit float support 2025-01-21 21:06:12 +01:00
tools tools/target_swr_fuzzer: do not use negative numbers of samples 2025-01-21 22:55:10 +01:00
.gitattributes lavf/assenc: normalize line endings to \n 2024-02-11 17:01:07 -08:00
.gitignore .gitignore: add exclusions for shader .c files 2024-11-18 07:54:21 +01:00
.mailmap mailmap: add entry for myself 2024-07-15 01:59:37 +02:00
Changelog avformat/matroska: add support for VVC streams 2025-01-12 11:13:31 -03:00
configure avfilter/avfilter: Add FFFilter, hide internals of AVFilter 2025-01-12 15:41:40 +01:00
CONTRIBUTING.md
COPYING.GPLv2
COPYING.GPLv3
COPYING.LGPLv2.1
COPYING.LGPLv3
CREDITS
INSTALL.md INSTALL: explain the circular dependency issue and solution 2024-11-03 19:35:23 +01:00
LICENSE.md
MAINTAINERS MAINTAINERS: Lauri is still available but is really low on time nowadays 2024-11-28 23:19:00 +01:00
Makefile configure: Add wasm as a fake arch 2024-12-04 16:43:06 +08:00
README.md
RELEASE RELEASE: update release number after release/7.1 branch 2024-10-09 01:55:50 +02:00

FFmpeg README

FFmpeg is a collection of libraries and tools to process multimedia content such as audio, video, subtitles and related metadata.

Libraries

  • libavcodec provides implementation of a wider range of codecs.
  • libavformat implements streaming protocols, container formats and basic I/O access.
  • libavutil includes hashers, decompressors and miscellaneous utility functions.
  • libavfilter provides means to alter decoded audio and video through a directed graph of connected filters.
  • libavdevice provides an abstraction to access capture and playback devices.
  • libswresample implements audio mixing and resampling routines.
  • libswscale implements color conversion and scaling routines.

Tools

  • ffmpeg is a command line toolbox to manipulate, convert and stream multimedia content.
  • ffplay is a minimalistic multimedia player.
  • ffprobe is a simple analysis tool to inspect multimedia content.
  • Additional small tools such as aviocat, ismindex and qt-faststart.

Documentation

The offline documentation is available in the doc/ directory.

The online documentation is available in the main website and in the wiki.

Examples

Coding examples are available in the doc/examples directory.

License

FFmpeg codebase is mainly LGPL-licensed with optional components licensed under GPL. Please refer to the LICENSE file for detailed information.

Contributing

Patches should be submitted to the ffmpeg-devel mailing list using git format-patch or git send-email. Github pull requests should be avoided because they are not part of our review process and will be ignored.