[Playlist] First XSPF-related security issue? -- was: Re: [oss-security] CVE id request: vlc

Sebastian Pipping webmaster at hartwork.org
Wed Oct 15 14:48:35 UTC 2008


What I find especially interesting here is that
<identifier> is specified to hold a URI.  A number
is just a very special case of a relative URI...

Also I really hope this

  <location>C:\My%20Music\playlist.xspf</location>

is not what VLC was/is producing.

Robert, thanks for letting us know.



Sebastian



More information about the Playlist mailing list