The vulnerability in question is a Use After Free. Google used AI to find this bug, it would've taken them 3 seconds to fix it. Burning cash to generate spam bug reports to burden volunteer projects when you have the extra cash to burn to just fix the damn issue leaves a very sour taste in my mouth.
Notably, the vulnerability is also in a part which isn't included by default and nobody uses. I'm not sure that even warrants a CVE? A simple bug report would have probably been fine. If they think this is really a CVE, a bug fix commit would have been warranted.
FFmpeg to Google: Fund us or stop sending bugs
91–100 of 913 posts
Re: FFmpeg to Google: Fund us or stop sending bugs
#92Re: FFmpeg to Google: Fund us or stop sending bugs
#93Re: FFmpeg to Google: Fund us or stop sending bugs
#94From TFA this was telling: Thus, as Mark Atwood, an open source policy expert, pointed out on Twitter, he had to keep telling Amazon to not do things that would mess up FFmpeg because, he had to keep explaining to his bosses that “They are not a vendor, there is no NDA, we have no leverage, your VP has refused to help fund them, and they could kill three major product lines tomorrow with an email. So, stop, and liste…
Google is not paying anyone to find bugs. They are running AIs indiscriminately.
Re: FFmpeg to Google: Fund us or stop sending bugs
#95Earlier quoted context omitted.
It’s not bug reports. It’s CVE. There is a convergence of very annoying trends happening: more and more are garbage found and written using AI and with an impact which is questionable at best, the way CVE are published and classified is idiotic and platform founding vulnerability research like Google are more and more hostile to projects leaving very little time to actually work on fixes before publishing. This is le…
The lowered lead times are because devs have an entitled additude that others fix their code when they discover bugs in it. The 90 day period is the grace period for the dev, not a demand. If they don't want to fix it then it goes public.
That’s how open source works.
Re: FFmpeg to Google: Fund us or stop sending bugs
#96Probably could pull in millions per year.
Re: FFmpeg to Google: Fund us or stop sending bugs
#97Does Google seriously not have a whole team of people who help maintain ffmpeg?
Re: FFmpeg to Google: Fund us or stop sending bugs
#98Earlier quoted context omitted.
CVEs aren't caused by bugs?
You could argue that, but I think that a bug is the software failing to do what it was specified, or what it promised to do. If security wasn't promised, it's not a bug.
Re: FFmpeg to Google: Fund us or stop sending bugs
#99Earlier quoted context omitted.
How could ffmpeg maintainers kill three major AWS product lines with an email?
Easy: ffmpeg discontinues or relicenses some ffmpeg functionality that AWS depends on for those product alines and AWS is screwed. I've seen that happen in other open source projects.
Re: FFmpeg to Google: Fund us or stop sending bugs
#100The vulnerability in question is a Use After Free. Google used AI to find this bug, it would've taken them 3 seconds to fix it. Burning cash to generate spam bug reports to burden volunteer projects when you have the extra cash to burn to just fix the damn issue leaves a very sour taste in my mouth.
Notably, the vulnerability is also in a part which isn't included by default and nobody uses. I'm not sure that even warrants a CVE? A simple bug report would have probably been fine. If they think this is really a CVE, a bug fix commit would have been warranted.