mpv media player – mf custom protocol vulnerability (CVE-2021-30145)
The mpv media player provides a custom protocol handler (mf://) in order to merge multiple images to a video. An undocumented feature within this protocol handler allows the usage of a format specifier in the provided URL, which is evaluated using sprintf. This results in both, a format string vulnerability as well as a heap … Continue reading mpv media player – mf custom protocol vulnerability (CVE-2021-30145)
Copy and paste this URL into your WordPress site to embed
Copy and paste this code into your site to embed