Earlier quoted context omitted.
They're also extremely hostile to security researchers who report these issues.
https://x.com/ffmpeg/status/2039115531744334180?s=46&t=qCSkw... Security is the punch line for ffmpeg.
Twenty One Zero-Days in FFmpeg
41–50 of 216 posts
Re: Twenty One Zero-Days in FFmpeg
#42Re: Twenty One Zero-Days in FFmpeg
#43Earlier quoted context omitted.
They're also extremely hostile to security researchers who report these issues.
https://x.com/ffmpeg/status/2039115531744334180?s=46&t=qCSkw... Security is the punch line for ffmpeg.
Re: Twenty One Zero-Days in FFmpeg
#44That's not what "zero-day" means.
It seems to have lost its meaning after getting popularized following Stuxnet coverage.
I understand why it's poorly understood. It's a snappy term, and people assume it means "bad" and nothing else because that's all you can get from the context. However, since most people also don't know the difference between a vulnerability and an exploit, they won't understand the definition of a zero-day when they read it.
But I'm still going to complain if a security vulnerability research company is using the term incorrectly in their own press copy. It makes them look amateurish.
Re: Twenty One Zero-Days in FFmpeg
#45Ffmpeg has an exceptionally terrible track record when it comes to security. People have been throwing fuzzers at it for as long as I remember and coming back with a nearly inexhaustible supply of memory corruption bugs. Here's an effort by one Googler a decade ago: https://security.googleblog.com/2014/01/ffmpeg-and-thousand-... So, while it's a demo of the capabilities of LLMs, this should not be at all surprising.…
They're also extremely hostile to security researchers who report these issues.
Do you have an example?
Re: Twenty One Zero-Days in FFmpeg
#46Ffmpeg has an exceptionally terrible track record when it comes to security. People have been throwing fuzzers at it for as long as I remember and coming back with a nearly inexhaustible supply of memory corruption bugs. Here's an effort by one Googler a decade ago: https://security.googleblog.com/2014/01/ffmpeg-and-thousand-... So, while it's a demo of the capabilities of LLMs, this should not be at all surprising.…
[flagged]
Re: Twenty One Zero-Days in FFmpeg
#47I find difficult to know how serious the issue is, if it is even an issue. LLM constantly confidently giving me this same sounding script with a "the root cause" and how it "is simple" while being completely incorrect.
Re: Twenty One Zero-Days in FFmpeg
#48Re: Twenty One Zero-Days in FFmpeg
#49Earlier quoted context omitted.
They're also extremely hostile to security researchers who report these issues.
> … hostile to security researchers who report these issues. Do you have an example?
Re: Twenty One Zero-Days in FFmpeg
#50Ffmpeg has an exceptionally terrible track record when it comes to security. People have been throwing fuzzers at it for as long as I remember and coming back with a nearly inexhaustible supply of memory corruption bugs. Here's an effort by one Googler a decade ago: https://security.googleblog.com/2014/01/ffmpeg-and-thousand-... So, while it's a demo of the capabilities of LLMs, this should not be at all surprising.…
Is GStreamer a more secure alternative or does it just get a bit less attention than ffmpeg?