On Tue, Apr 07, 2020 at 10:55:39AM +0200, Paul B Mahol wrote: > On 4/6/20, Michael Niedermayer <mich...@niedermayer.cc> wrote: > > On Mon, Apr 06, 2020 at 12:00:21PM +0200, Anton Khirnov wrote: > >> Quoting Michael Niedermayer (2020-04-05 00:38:41) > >> > Fixes: memleak > >> > >> Memleak of what/where/why? This is highly non-obvious. > > > > yes, i tend to be terse on "security" fixes so as not to provide a > > "how to exploit" > > > > what leaks is the AVVorbisParseContext it leaks as there is no check for it > > being already allocated. > > I attempted to add such a check but that was rejected by paul with no > > further > > comment. > > See: 0113 10:59 To FFmpeg devel (1,4K) [FFmpeg-devel] [PATCH] > > avformat/oggparsevorbis: Error out on double init of vp > > > > This patch works around that by preventing the demuxer allocated extradata > > from being replaced by the NULL extradata from the decoder > > As there is a check for double allocating the extradata that will protect > > also from AVVorbisParseContext double allocation > > > > that said, the whole back and forth copying of parameters we have in > > libavformat now a days is not pretty and every time i look at it it > > feels fragile. Iam a bit surprised this doesnt cause more problems > > > > There are of course other ways to fix this, i did tend towards a > > simple (hopefully) easy to backport fix > > > > What do you prefer ? > > I rejected patch, because Lynee reported over IRC, which you > thankfully completely ignored, bug that stops playing files.
i must have forgotten. I dont remember Can you or someone tell me what bug this is about or which ticket this is about if theres a ticket? Thanks [...] -- Michael GnuPG fingerprint: 9FF2128B147EF6730BADF133611EC787040B0FAB Those who are best at talking, realize last or never when they are wrong.
signature.asc
Description: PGP signature
_______________________________________________ ffmpeg-devel mailing list ffmpeg-devel@ffmpeg.org https://ffmpeg.org/mailman/listinfo/ffmpeg-devel To unsubscribe, visit link above, or email ffmpeg-devel-requ...@ffmpeg.org with subject "unsubscribe".