Live data from Hacker News

Twenty One Zero-Days in FFmpeg

depthfirst.com

41–50 of 216 posts

Re: Twenty One Zero-Days in FFmpeg

#41
post #23

Earlier quoted context omitted.

They're also extremely hostile to security researchers who report these issues.

https://x.com/ffmpeg/status/2039115531744334180?s=46&t=qCSkw... Security is the punch line for ffmpeg.

Oh my god! They are so funny and memeable! gets RCE'd

Re: Twenty One Zero-Days in FFmpeg

#43
post #23

Earlier quoted context omitted.

They're also extremely hostile to security researchers who report these issues.

https://x.com/ffmpeg/status/2039115531744334180?s=46&t=qCSkw... Security is the punch line for ffmpeg.

I'm glad to see their sense of humour :-)

https://nitter.net/ffmpeg/status/2039115531744334180

Re: Twenty One Zero-Days in FFmpeg

#44

That's not what "zero-day" means.

It seems to have lost its meaning after getting popularized following Stuxnet coverage.

No, I think it was since Code Red.

I understand why it's poorly understood. It's a snappy term, and people assume it means "bad" and nothing else because that's all you can get from the context. However, since most people also don't know the difference between a vulnerability and an exploit, they won't understand the definition of a zero-day when they read it.

But I'm still going to complain if a security vulnerability research company is using the term incorrectly in their own press copy. It makes them look amateurish.

Re: Twenty One Zero-Days in FFmpeg

#45
post #23

Ffmpeg has an exceptionally terrible track record when it comes to security. People have been throwing fuzzers at it for as long as I remember and coming back with a nearly inexhaustible supply of memory corruption bugs. Here's an effort by one Googler a decade ago: https://security.googleblog.com/2014/01/ffmpeg-and-thousand-... So, while it's a demo of the capabilities of LLMs, this should not be at all surprising.…

They're also extremely hostile to security researchers who report these issues.

> … hostile to security researchers who report these issues.

Do you have an example?

Re: Twenty One Zero-Days in FFmpeg

#46

Ffmpeg has an exceptionally terrible track record when it comes to security. People have been throwing fuzzers at it for as long as I remember and coming back with a nearly inexhaustible supply of memory corruption bugs. Here's an effort by one Googler a decade ago: https://security.googleblog.com/2014/01/ffmpeg-and-thousand-... So, while it's a demo of the capabilities of LLMs, this should not be at all surprising.…

[flagged]

You should rethink this kind of casual racism.

Re: Twenty One Zero-Days in FFmpeg

#47

I find difficult to know how serious the issue is, if it is even an issue. LLM constantly confidently giving me this same sounding script with a "the root cause" and how it "is simple" while being completely incorrect.

Its 21 issues. And they've been human validated, as far as I can tell.

Re: Twenty One Zero-Days in FFmpeg

#49
post #23

Earlier quoted context omitted.

They're also extremely hostile to security researchers who report these issues.

> … hostile to security researchers who report these issues. Do you have an example?

I have numerous examples of security researchers being hostile and impossible to work with (but cannot share them unfortunately).

Re: Twenty One Zero-Days in FFmpeg

#50

Ffmpeg has an exceptionally terrible track record when it comes to security. People have been throwing fuzzers at it for as long as I remember and coming back with a nearly inexhaustible supply of memory corruption bugs. Here's an effort by one Googler a decade ago: https://security.googleblog.com/2014/01/ffmpeg-and-thousand-... So, while it's a demo of the capabilities of LLMs, this should not be at all surprising.…

Is GStreamer a more secure alternative or does it just get a bit less attention than ffmpeg?

In my experience it's mainly run by very grumpy and opinionated Europeans who take pride in having bugs old enough to drink.
Post reply on HN