Posted by trollied 2 days ago
To explain, Googles vulnerability scanner found a problem in an obscure decoder for a 1990s game files (Lucasfilm Smush). Devs are not happy they get timewasting reports on stuff that rarely anyone ever uses except an exceptionally tiny group.
Then people start berating them without even knowing the full story...
They should be building ffmpeg with a minimal feature set anyway, so none of these obscure codecs end up included in the final binary.
Run the following command to confirm:
ffmpeg -codecs|grep sanm
It's enabled by default so all that's required to exploit it would be to construct a payload file and name it movie.mp4
In such a would they might even handball submitted obscure codecs to a full build in a sandbox to track bleeding edge malware.
Indeed. A step so obvious it renders comments such as this:
  It's enabled by default so all that's required to exploit it would be to construct a payload file and name it movie.mp4
moot.> Which is exactly why reporting the bug is a FAVOR to ffmpeg.
Not sure you have to SHOUT the obvious.
> Would you rather they just quietly fix it on their own and not report it to the maintainers?
What do you suppose the answer to that question to be?
But she ends up getting more criticism than the billionaire who donates nothing. Seems unfair but I guess it's human nature.
Reminds me of gstreamer plugins being separated in "base", "good", "bad" and "ugly" sets.
Normally if a bug is found in a open source project, then its common courtesy to propose a patch to fix it. Hell when you do red team security research on a codebase your supposed to identify the root cause in code or human behavior and propose a fix/patch if you have access to the code.
They should have included a patch though and they should have contacted ffmpeg team first before spamming them with dozens of issues all at once.
I don't know how a vulnerability report could be much better than that. It is a real vulnerability. The report includes a detailed analysis of where the vulnerability is. The bug has been validated, and the report includes exact reproduction instructions.
How is that a bullshit bug report?
The human idiot "researchers" will send paragraph long automatically generated extortion threats over not sending HSTS header