Viewing profile — ChALkeR
ChALkeR
HN member- Joined
- Sun, Dec 06, 2015, 10:21 PM UTC
- HN karma
- 66
- Public activity
- 31 items
- HN profile
- View on Hacker News ↗
About ChALkeR
Recent public activity
- story
-
comment
Comment #14613582
The correct figure is 10%.
- story
- story
-
comment
Comment #10909877
Done: https://news.ycombinator.com/item?id=10909727
-
comment
Comment #10909735
I tried hard to cover all the possible question. Please, read the post _carefully_ before asking or proposing anything.
- story
-
comment
Comment #10902764
Note: this actually means that everyone should regenerate all their key-pairs after updating.
-
comment
Comment #10899179
And no, switching Buffer(number) to be zero-filled will bring more harm now, even from the security point of view. The best course of action imo is to deprecate Buffer(number) what…
-
comment
Comment #10899040
This note does not have anything actually new, but I have seen several people who are not aware of that.
- story
-
comment
Comment #10898578
Looks like it bundles libavformat internally.
-
comment
Comment #10898553
By the way, mplayer is also affected, even after installing a fixed version of ffmpeg.
-
comment
Comment #10897769
It does not, that's covered in the original article.
-
comment
Comment #10897353
But that code that you linked to does not verify that the file is mp4, moreover, mp4Sig call is commented out.
-
comment
Comment #10895897
Tell me if I should not have double-posted it here, I will delete one of those posts then.
-
comment
Comment #10895886
Re-posted as https://news.ycombinator.com/item?id=10895872
-
comment
Comment #10895885
Short English description: ffmpeg vulnerability allows reading local files and sending them over network using a specially crafted video file. This affects not only file conversion…
-
comment
Comment #10895880
Previosly posted as https://news.ycombinator.com/item?id=10893301 , but that eneded up in [ask] due to my mistake.
- story
-
comment
Comment #10895719
https://translate.google.com/translate?sl=ru&tl=en&u=http%3A... will work better, I suppose.
-
comment
Comment #10895710
Should I post this again with a link so it ends up in the news or not?
-
comment
Comment #10895475
Hm. Why did this end up in [ask]? Perhaps I made a mistake when posting this =).
-
comment
Comment #10893418
It's «PC» as in «server»/«PC», not as in «mac»/«PC».
-
story
Tell HN: Ffmpeg vulnerability allows attacker to get files from server or PC
ffmpeg vulnerability allows reading local files and sending them over network using a specially crafted video file. This affects not only file conversion (including thumbnail gener…