Earlier quoted context omitted.
Where do you draw the line? Do you want Google to just not inspect any projects that it can't fully commit to maintaining? Providing a real CVE is a contribution, not a burden. The ffmpeg folks can ignore it, since by all indications it's pretty minor.
> Providing a real CVE is a contribution, not a burden. The ffmpeg folks can ignore it, since by all indications it's pretty minor. Re-read the article. There's CVEs and then there's CVEs . This is the former, and they're shoving tons of those down the throats of unpaid volunteers while contributing nothing back. What Google's effectively doing is like a food safety inspection company going to the local food bank to…
This is exploitable on a majority of systems as the codec is enabled by default. This is a CVE that is being severely underestimated.