[vlc-devel] [PATCH 1/2] cli: remove TCP mode (--rc-host)

Rémi Denis-Courmont remi at remlab.net
Sat Nov 21 15:04:58 CET 2020


Le lauantaina 21. marraskuuta 2020, 13.10.20 EET Alexandre Janniaux a écrit :
> Hi,
> 
> That's litterally my only use case for the Cli interface
> and was a point that I shared and used for the transition
> from lua RC to C RC. If this is to be merged, then there's
> no point in replacing the lua RC and I'll vote for restoring
> the lua RC.

That's literally an RCE in disguise, and it's equally a problem with Lua or C. 
This has nothing to do with which language to use. This needs to be removed 
either way.

Do I need to file a CVE for people to start caring about security?

-- 
レミ・デニ-クールモン
http://www.remlab.net/





More information about the vlc-devel mailing list