diff options
author | wm4 <wm4@nowhere> | 2014-09-16 18:23:01 +0200 |
---|---|---|
committer | wm4 <wm4@nowhere> | 2014-09-16 18:23:01 +0200 |
commit | d83a9f7f03c41d9138390ffe7789e5bb7d3e7ac2 (patch) | |
tree | fdacb8da3a015440816c83b9e70b43be67a5dde2 /DOCS | |
parent | caaeb15318dbdd38344f15a8919540f188de5c46 (diff) | |
download | mpv-d83a9f7f03c41d9138390ffe7789e5bb7d3e7ac2.tar.bz2 mpv-d83a9f7f03c41d9138390ffe7789e5bb7d3e7ac2.tar.xz |
player: don't let multiline filenames set options on resume
If --write-filename-in-watch-later-config is used, and the filename
contains newline characters (as generally allowed on Unix), then the
newline will be written to the resume file literally, and the parts
after the newline character are interpreted as options.
This is possibly security relevant.
Change newline characters (and in fact any other special characters)
to '_'.
Reported as #1099 (this commit is a reimplementation of the proposed
pull request).
CC: @mpv-player/stable
Diffstat (limited to 'DOCS')
0 files changed, 0 insertions, 0 deletions