Hello community, here is the log from the commit of package mpv for openSUSE:Factory checked in at 2018-02-10 18:00:20 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/mpv (Old) and /work/SRC/openSUSE:Factory/.mpv.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "mpv" Sat Feb 10 18:00:20 2018 rev:43 rq:575224 version:unknown Changes: -------- --- /work/SRC/openSUSE:Factory/mpv/mpv.changes 2017-12-19 10:51:49.516647131 +0100 +++ /work/SRC/openSUSE:Factory/.mpv.new/mpv.changes 2018-02-10 18:00:21.687366242 +0100 @@ -1,0 +2,9 @@ +Sat Feb 10 14:11:42 UTC 2018 - [email protected] + +- Update to version 0.27.1 + * This release fixes CVE-2018-6360 (boo#1077894) + Fixes and minor enhancements + * ytdl_hook: whitelist protocols from urls retrieved from + youtube-dl (#5456) + +------------------------------------------------------------------- Old: ---- mpv-0.27.0.tar.gz New: ---- mpv-0.27.1.tar.gz ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ mpv.spec ++++++ --- /var/tmp/diff_new_pack.hndi2L/_old 2018-02-10 18:00:23.055316722 +0100 +++ /var/tmp/diff_new_pack.hndi2L/_new 2018-02-10 18:00:23.063316432 +0100 @@ -1,7 +1,7 @@ # # spec file for package mpv # -# Copyright (c) 2017 SUSE LINUX GmbH, Nuernberg, Germany. +# Copyright (c) 2018 SUSE LINUX GmbH, Nuernberg, Germany. # Copyright (c) 2015 Packman Team <[email protected]> # Copyright (c) 2012 Jiri Slaby <[email protected]> # Copyright (c) 2011-2012 Pascal Bleser <[email protected]> @@ -21,7 +21,7 @@ %define _waf_ver 1.9.13 %define _mbc_ver 3.3.16 -%define _mpv_ver 0.27.0 +%define _mpv_ver 0.27.1 %define lname libmpv1 Name: mpv Version: %{_mpv_ver} ++++++ mpv-0.27.0.tar.gz -> mpv-0.27.1.tar.gz ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/mpv-0.27.0/RELEASE_NOTES new/mpv-0.27.1/RELEASE_NOTES --- old/mpv-0.27.0/RELEASE_NOTES 2017-09-13 03:40:14.000000000 +0200 +++ new/mpv-0.27.1/RELEASE_NOTES 2018-02-10 13:45:10.000000000 +0100 @@ -1,3 +1,12 @@ +Release 0.27.1 +============== + +This releaes fixes CVE-2018-6360. + +Fixes and Minor Enhancements +---------------------------- +- ytdl_hook: whitelist protocols from urls retrieved from youtube-dl (#5456) + Release 0.27.0 ============== diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/mpv-0.27.0/VERSION new/mpv-0.27.1/VERSION --- old/mpv-0.27.0/VERSION 2017-09-13 03:40:14.000000000 +0200 +++ new/mpv-0.27.1/VERSION 2018-02-10 13:45:10.000000000 +0100 @@ -1 +1 @@ -0.27.0 +0.27.1 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/mpv-0.27.0/player/lua/ytdl_hook.lua new/mpv-0.27.1/player/lua/ytdl_hook.lua --- old/mpv-0.27.0/player/lua/ytdl_hook.lua 2017-09-13 03:40:14.000000000 +0200 +++ new/mpv-0.27.1/player/lua/ytdl_hook.lua 2018-02-10 13:45:10.000000000 +0100 @@ -15,6 +15,18 @@ local chapter_list = {} +function Set (t) + local set = {} + for _, v in pairs(t) do set[v] = true end + return set +end + +local safe_protos = Set { + "http", "https", "ftp", "ftps", + "rtmp", "rtmps", "rtmpe", "rtmpt", "rtmpts", "rtmpte", + "data" +} + local function exec(args) local ret = utils.subprocess({args = args}) return ret.status, ret.stdout, ret @@ -71,6 +83,15 @@ return "%" .. string.len(url) .. "%" .. url end +local function url_is_safe(url) + local proto = type(url) == "string" and url:match("^(.+)://") or nil + local safe = proto and safe_protos[proto] + if not safe then + msg.error(("Ignoring potentially unsafe url: '%s'"):format(url)) + end + return safe +end + local function time_to_secs(time_string) local ret @@ -182,6 +203,9 @@ for i = offset, #fragments do local fragment = fragments[i] + if not url_is_safe(join_url(base, fragment)) then + return nil + end table.insert(parts, edl_escape(join_url(base, fragment))) if fragment.duration then parts[#parts] = @@ -201,6 +225,9 @@ edl_track = edl_track_joined(track.fragments, track.protocol, json.is_live, track.fragment_base_url) + if not edl_track and not url_is_safe(track.url) then + return + end if track.acodec and track.acodec ~= "none" then -- audio track mp.commandv("audio-add", @@ -217,6 +244,9 @@ edl_track = edl_track_joined(json.fragments, json.protocol, json.is_live, json.fragment_base_url) + if not edl_track and not url_is_safe(json.url) then + return + end -- normal video or single track streamurl = edl_track or json.url set_http_headers(json.http_headers) @@ -408,6 +438,10 @@ msg.debug("EDL: " .. playlist) + if not playlist then + return + end + -- can't change the http headers for each entry, so use the 1st if json.entries[1] then set_http_headers(json.entries[1].http_headers) @@ -455,14 +489,14 @@ add_single_video(json.entries[1]) else - local playlist = "#EXTM3U\n" + local playlist = {"#EXTM3U"} for i, entry in pairs(json.entries) do local site = entry.url local title = entry.title if not (title == nil) then title = string.gsub(title, '%s+', ' ') - playlist = playlist .. "#EXTINF:0," .. title .. "\n" + table.insert(playlist, "#EXTINF:0," .. title) end -- some extractors will still return the full info for @@ -475,10 +509,17 @@ site = entry["webpage_url"] end - playlist = playlist .. "ytdl://" .. site .. "\n" + -- links with only youtube id as returned by --flat-playlist + if not site:find("://") then + table.insert(playlist, "ytdl://" .. site) + elseif url_is_safe(site) then + table.insert(playlist, site) + end end - mp.set_property("stream-open-filename", "memory://" .. playlist) + if #playlist > 0 then + mp.set_property("stream-open-filename", "memory://" .. table.concat(playlist, "\n")) + end end else -- probably a video
