java-topology/defects/ffmpeg/patch
russell@unturf.com 409d0f1907 imagemagick+ffmpeg: 5-MOAD scan; ffmpeg-0004 CWE-312 Authorization header logged at AV_LOG_DEBUG
ffmpeg-0004 (MOAD-0004 / CWE-312): libavformat/http.c http_connect() logs the full
HTTP request at AV_LOG_DEBUG, including the Authorization: Basic header with
base64-encoded user:pass. Fix: produce a sanitized copy before av_log, replacing
auth header values with ***REDACTED***. Wire bytes unchanged. 22/22 unit tests PASS.

FFmpeg MOADs 0002/0003/0005: CLEAN. ImageMagick MOADs 0002-0005: CLEAN.
2026-03-31 21:10:24 -04:00
..
ffmpeg-0001-filtergraph-format-merge-n2.patch curl/ffmpeg: CWE-407 findings — awssigv4 bubble sort + filtergraph format merge 2026-03-30 09:38:07 -04:00
ffmpeg-0001.patch whitepaper: re-add 10 missing entries + 11 new defects this session, count 578→590; rebuild PDF 2026-03-27 22:18:31 -04:00
ffmpeg-0002-gif-shrink-palette-hashset.md undf: assign 681-693; stamp 20 patches; numpy/pandas/scipy/scylladb/clickhouse/cockroachdb/duckdb/moby/simplex-chat new defects 2026-03-29 22:05:46 -04:00
ffmpeg-0002.patch undf: assign 694-720; stamp patches; ruby-0003/elixir-0002/r-source-0002/victoria-metrics-0002 2026-03-29 22:28:31 -04:00
ffmpeg-0003.patch undf: assign 694-720; stamp patches; ruby-0003/elixir-0002/r-source-0002/victoria-metrics-0002 2026-03-29 22:28:31 -04:00
ffmpeg-0004-http-auth-debug-log-credential-leak.patch imagemagick+ffmpeg: 5-MOAD scan; ffmpeg-0004 CWE-312 Authorization header logged at AV_LOG_DEBUG 2026-03-31 21:10:24 -04:00
ffmpeg-deeper-scan-CLEAN.md bazel-0003 + kicad-0002: build toolchain feature check + PCB zone filler O(Z²×L²); count 601→603 2026-03-27 22:38:32 -04:00
ffmpeg-moad-0002-0005-scan.md imagemagick+ffmpeg: 5-MOAD scan; ffmpeg-0004 CWE-312 Authorization header logged at AV_LOG_DEBUG 2026-03-31 21:10:24 -04:00