This is an automated email from the git hooks/post-receive script.

Git pushed a commit to branch master
in repository ffmpeg.

commit 7530aa12ee9e0ee33d5dfc2336411acae378ebf1
Author:     Niklas Haas <[email protected]>
AuthorDate: Mon Jun 29 15:45:18 2026 +0200
Commit:     Kacper Michajłow <[email protected]>
CommitDate: Mon Jul 27 17:05:20 2026 +0000

    avformat/libcurl: avoid integer overflow in connect_timeout
    
    This is multiplied by 1000, which can overflow on systems with 32-bit
    long (i.e. most of them).
    
    Sponsored-by: nxtedition AB
    Signed-off-by: Niklas Haas <[email protected]>
---
 libavformat/libcurl.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/libcurl.c b/libavformat/libcurl.c
index 1823ba7a3a..acd5618a41 100644
--- a/libavformat/libcurl.c
+++ b/libavformat/libcurl.c
@@ -1145,7 +1145,7 @@ static const AVOption options[] = {
     { "ca_file", "certificate authority bundle file", OFFSET(ca_file), 
AV_OPT_TYPE_STRING, { .str = NULL }, 0, 0, D | E },
     { "cert_file", "client certificate file", OFFSET(cert_file), 
AV_OPT_TYPE_STRING, { .str = NULL }, 0, 0, D | E },
     { "key_file", "client private key file", OFFSET(key_file), 
AV_OPT_TYPE_STRING, { .str = NULL }, 0, 0, D | E },
-    { "connect_timeout", "connection timeout in seconds (0 = libcurl 
default)", OFFSET(connect_timeout), AV_OPT_TYPE_INT, { .i64 = 0 }, 0, INT_MAX, 
D | E },
+    { "connect_timeout", "connection timeout in seconds (0 = libcurl 
default)", OFFSET(connect_timeout), AV_OPT_TYPE_INT, { .i64 = 0 }, 0, INT_MAX / 
1000, D | E },
     { "max_redirects", "maximum number of redirects to follow", 
OFFSET(max_redirects), AV_OPT_TYPE_INT, { .i64 = 16 }, 0, INT_MAX, D },
     { "multiple_requests", "reuse the connection across requests (HTTP 
keep-alive)", OFFSET(multiple_requests), AV_OPT_TYPE_BOOL, { .i64 = 1 }, 0, 1, 
D | E },
     { "max_retries", "maximum number of retries after a recoverable error", 
OFFSET(max_retries), AV_OPT_TYPE_INT, { .i64 = 5 }, 0, INT_MAX, D },

_______________________________________________
ffmpeg-cvslog mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to