5 ms·
I wonder if this vulnerable codec is enabled by default when building FFmpeg? Because if so, then it doesn't matter that it's a "1990s game codec" because any a
by vqtska 11mo ago
I wonder if this vulnerable codec is enabled by default when building FFmpeg? Because if so, then it doesn't matter that it's a "1990s game codec" because any application using FFmpeg to accept arbitrary video files is vulnerable to memory corruption, which should probably be taken more seriously.
- chemotaxis 11mo agoThe somewhat depressing reality is that if you're running ffmpeg on user-supplied multimedia without putting it in a bulletproof sandbox, you're just bound to have a bad time. Video decoding is one of these things that no one seems to know how to do safely in C or C++, not in the long haul. And that's probably fine, because we have lightweight sandboxing tech that makes this largely moot - but there's an extra step you need to take. Maybe it's on the ffmpeg project that they don't steer people in that direction. Trying to fix these bugs piecemeal is somewhat pointless - or at least, we've been trying for several decades, throwing a ton of manpower and compute at it, and we're still nowhere near a point where you could say "this is safe".
- ozgrakkurt 11mo agoDoes this mean we have to run vlc in a sandbox while watching a downloaded film?
- awakeasleep 11mo agoIn production? With a user-supplied film? You seem to be captured by the “all or nothing” security fallacy, when security must be viewed through the lens of (probability) x (impact)
- ls612 11mo agoIt isn't even like this is without precedent, the FORCEDENTRY NSO kit used the shitty old JBIG2 parser that Apple was shipping as its entry point despite the fact that approximately nobody was legitimately using JBIG2 in iMessage.
- deleted 11mo ago[deleted]
- hulitu 11mo ago> despite the fact that approximately nobody was legitimately using JBIG2 in iMessage. Then why it has been enabled ? Asking for a friend. /s Unless Apple, ffmpeg has a reason to enable old codecs. If you only need a subset: configure; make; make install
- astrange 11mo ago> Then why it has been enabled ? Asking for a friend. /s Because it's in the PDF spec, and you can't randomly disable parts of that.
- plorkyeran 11mo agoNo, all the ancient video game codecs and other such things that are there for historical preservation purposes but are rarely actually used are disabled by default and you have to really go out of your way to enable them. This was originally for binary size/build time reasons.
- IshKebab 11mo agoAre you sure? I ran `ffmpeg -codecs` on Ubuntu and it lists D.V.L. sanm LucasArts SANM/SMUSH video
- deleted 11mo ago[deleted]
- IshKebab 11mo agoI checked with Ubuntu's ffmpeg and it is enabled by default. There are a huge list of codecs enabled by default (maybe all of them?). Given the security track record of codecs implemented in C, this means it's basically guaranteed that there are dozens of security vulnerabilities in ffmpeg. I think the same is probably true for VLC to a lesser extent, which is pretty wild considering I've never heard of it being used as an attack vector, e.g. via torrents.
- haskellshill 11mo agoVLC is pretty popular on windows, but ffmpeg? Is there any commonly used windows app that relies on it? I doubt it'd be worth one's time to write exploits for desktop linux
- michaelt 11mo agoDepends if any important websites are re-compressing user-uploaded videos. If there's a website converting user-uploaded gifs to mp4 to save on bandwidth or something, I wouldn't be surprised if they used ffmpeg to do it.
- dpe82 11mo agoVLC and ffmpeg share the same underlying library family (libav*) where this vulnerability lives. > I doubt it'd be worth one's time to write exploits for desktop Linux How many developers, network administrators, etc. run desktop Linux? Gaining access to those can be very, very valuable.
- brigade 11mo agoFFmpeg based players have been popular for 20 years now. Has there been a single documented actual use of their libraries as the exploitation vector anytime in the last two decades?
- dpe82 11mo agoI'm certain it's happened but since I don't have one off the top of my head I'll instead point out a related issue: https://en.wikipedia.org/wiki/Stagefright_(bug) https://en.wikipedia.org/wiki/Stagefright_(bug) It's worth pointing out that many, many, many things use the libav* library family.