[FFmpeg-devel] Would a crypto file be acceptable?

Nicolas George george at nsup.org
Mon Dec 26 13:24:21 EET 2022


Tomas Härdin (12022-12-26):
> Right. And trying to smuggle in command line options via a file feels
> made for exploitation..

This is why my proposal years ago was rejected by Reimar.

And this is why concat requires -safe to accept options.

To be fair, limiting the case to cryptographic keys would probably not
be exploitable, but it is a half measure, too specific to a particular
use case.

-- 
  Nicolas George
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://ffmpeg.org/pipermail/ffmpeg-devel/attachments/20221226/8629f9bc/attachment.sig>


More information about the ffmpeg-devel mailing list