FFmpeg (@FFmpeg) on X

1 min read Original article ↗
  • user avatar

  • user avatar

    Care to explain why is it cve slop? In the end wasn't a real vulnerability that was eventually fixed?

  • user avatar

    I can just imagine what it must look like on your end; all these big banked corporations building revenue streams built in full, in part or assisted by OSS hobby code & their thank you for free stuff is a cve. “I solved the problem, I opened a ticket”

  • user avatar

    To be fair, is this be a vulnerability if you are accepting random untrusted input files? Is there a matrix of which codecs are considered stable (and hardened) and which are not to be trusted with arbitrary inputs? Not defending Google though, if they aren’t also offering fixes.