Hello community,

here is the log from the commit of package mpv for openSUSE:Factory checked in 
at 2018-02-10 18:00:20
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/mpv (Old)
 and      /work/SRC/openSUSE:Factory/.mpv.new (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "mpv"

Sat Feb 10 18:00:20 2018 rev:43 rq:575224 version:unknown

Changes:
--------
--- /work/SRC/openSUSE:Factory/mpv/mpv.changes  2017-12-19 10:51:49.516647131 
+0100
+++ /work/SRC/openSUSE:Factory/.mpv.new/mpv.changes     2018-02-10 
18:00:21.687366242 +0100
@@ -1,0 +2,9 @@
+Sat Feb 10 14:11:42 UTC 2018 - [email protected]
+
+- Update to version 0.27.1
+  * This release fixes CVE-2018-6360 (boo#1077894)
+  Fixes and minor enhancements
+  * ytdl_hook: whitelist protocols from urls retrieved from
+    youtube-dl (#5456)
+
+-------------------------------------------------------------------

Old:
----
  mpv-0.27.0.tar.gz

New:
----
  mpv-0.27.1.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ mpv.spec ++++++
--- /var/tmp/diff_new_pack.hndi2L/_old  2018-02-10 18:00:23.055316722 +0100
+++ /var/tmp/diff_new_pack.hndi2L/_new  2018-02-10 18:00:23.063316432 +0100
@@ -1,7 +1,7 @@
 #
 # spec file for package mpv
 #
-# Copyright (c) 2017 SUSE LINUX GmbH, Nuernberg, Germany.
+# Copyright (c) 2018 SUSE LINUX GmbH, Nuernberg, Germany.
 # Copyright (c) 2015 Packman Team <[email protected]>
 # Copyright (c) 2012 Jiri Slaby <[email protected]>
 # Copyright (c) 2011-2012 Pascal Bleser <[email protected]>
@@ -21,7 +21,7 @@
 
 %define _waf_ver 1.9.13
 %define _mbc_ver 3.3.16
-%define _mpv_ver 0.27.0
+%define _mpv_ver 0.27.1
 %define lname   libmpv1
 Name:           mpv
 Version:        %{_mpv_ver}

++++++ mpv-0.27.0.tar.gz -> mpv-0.27.1.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/mpv-0.27.0/RELEASE_NOTES new/mpv-0.27.1/RELEASE_NOTES
--- old/mpv-0.27.0/RELEASE_NOTES        2017-09-13 03:40:14.000000000 +0200
+++ new/mpv-0.27.1/RELEASE_NOTES        2018-02-10 13:45:10.000000000 +0100
@@ -1,3 +1,12 @@
+Release 0.27.1
+==============
+
+This releaes fixes CVE-2018-6360.
+
+Fixes and Minor Enhancements
+----------------------------
+- ytdl_hook:  whitelist protocols from urls retrieved from youtube-dl (#5456)
+
 Release 0.27.0
 ==============
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/mpv-0.27.0/VERSION new/mpv-0.27.1/VERSION
--- old/mpv-0.27.0/VERSION      2017-09-13 03:40:14.000000000 +0200
+++ new/mpv-0.27.1/VERSION      2018-02-10 13:45:10.000000000 +0100
@@ -1 +1 @@
-0.27.0
+0.27.1
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/mpv-0.27.0/player/lua/ytdl_hook.lua 
new/mpv-0.27.1/player/lua/ytdl_hook.lua
--- old/mpv-0.27.0/player/lua/ytdl_hook.lua     2017-09-13 03:40:14.000000000 
+0200
+++ new/mpv-0.27.1/player/lua/ytdl_hook.lua     2018-02-10 13:45:10.000000000 
+0100
@@ -15,6 +15,18 @@
 
 local chapter_list = {}
 
+function Set (t)
+    local set = {}
+    for _, v in pairs(t) do set[v] = true end
+    return set
+end
+
+local safe_protos = Set {
+    "http", "https", "ftp", "ftps",
+    "rtmp", "rtmps", "rtmpe", "rtmpt", "rtmpts", "rtmpte",
+    "data"
+}
+
 local function exec(args)
     local ret = utils.subprocess({args = args})
     return ret.status, ret.stdout, ret
@@ -71,6 +83,15 @@
     return "%" .. string.len(url) .. "%" .. url
 end
 
+local function url_is_safe(url)
+    local proto = type(url) == "string" and url:match("^(.+)://") or nil
+    local safe = proto and safe_protos[proto]
+    if not safe then
+        msg.error(("Ignoring potentially unsafe url: '%s'"):format(url))
+    end
+    return safe
+end
+
 local function time_to_secs(time_string)
     local ret
 
@@ -182,6 +203,9 @@
 
     for i = offset, #fragments do
         local fragment = fragments[i]
+        if not url_is_safe(join_url(base, fragment)) then
+            return nil
+        end
         table.insert(parts, edl_escape(join_url(base, fragment)))
         if fragment.duration then
             parts[#parts] =
@@ -201,6 +225,9 @@
             edl_track = edl_track_joined(track.fragments,
                 track.protocol, json.is_live,
                 track.fragment_base_url)
+            if not edl_track and not url_is_safe(track.url) then
+                return
+            end
             if track.acodec and track.acodec ~= "none" then
                 -- audio track
                 mp.commandv("audio-add",
@@ -217,6 +244,9 @@
         edl_track = edl_track_joined(json.fragments, json.protocol,
             json.is_live, json.fragment_base_url)
 
+        if not edl_track and not url_is_safe(json.url) then
+            return
+        end
         -- normal video or single track
         streamurl = edl_track or json.url
         set_http_headers(json.http_headers)
@@ -408,6 +438,10 @@
 
                 msg.debug("EDL: " .. playlist)
 
+                if not playlist then
+                    return
+                end
+
                 -- can't change the http headers for each entry, so use the 1st
                 if json.entries[1] then
                     set_http_headers(json.entries[1].http_headers)
@@ -455,14 +489,14 @@
                 add_single_video(json.entries[1])
             else
 
-                local playlist = "#EXTM3U\n"
+                local playlist = {"#EXTM3U"}
                 for i, entry in pairs(json.entries) do
                     local site = entry.url
                     local title = entry.title
 
                     if not (title == nil) then
                         title = string.gsub(title, '%s+', ' ')
-                        playlist = playlist .. "#EXTINF:0," .. title .. "\n"
+                        table.insert(playlist, "#EXTINF:0," .. title)
                     end
 
                     -- some extractors will still return the full info for
@@ -475,10 +509,17 @@
                         site = entry["webpage_url"]
                     end
 
-                    playlist = playlist .. "ytdl://" .. site .. "\n"
+                    -- links with only youtube id as returned by 
--flat-playlist
+                    if not site:find("://") then
+                        table.insert(playlist, "ytdl://" .. site)
+                    elseif url_is_safe(site) then
+                        table.insert(playlist, site)
+                    end
                 end
 
-                mp.set_property("stream-open-filename", "memory://" .. 
playlist)
+                if #playlist > 0 then
+                    mp.set_property("stream-open-filename", "memory://" .. 
table.concat(playlist, "\n"))
+                end
             end
 
         else -- probably a video



Reply via email to