Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <569640E3.3080009@openwall.com>
Date: Wed, 13 Jan 2016 15:19:47 +0300
From: Alexander Cherepanov <ch3root@...nwall.com>
To: oss-security@...ts.openwall.com
Subject: Re: Fwd: FFmpeg: stealing local files with HLS+concat

On 2016-01-13 14:01, Vladimir Dubrovin wrote:
> I've underestimated the impact of this bug, so it was full disclosured
> in this article (Russian language, but google translate works fine with
> it) - http://habrahabr.ru/company/mailru/blog/274855

By following links from there:
slides: http://www.slideshare.net/MailRuGroup/security-meetup-22-mailru
video: https://www.youtube.com/watch?v=HRNPnbxrSCo
(still both in Russian)

Somewhat related:
https://github.com/ctfs/write-ups-2015/tree/master/9447-ctf-2015/web/super-turbo-atomic-gif-converter

-- 
Alexander Cherepanov

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.