Zero-Day Vulnerability Discovered In FFmpeg Lets Attackers Steal Files Remotely
prisoninmate writes: A zero-day vulnerability in the FFmpeg open-source multimedia framework, which is currently used in numerous Linux kernel-based operating systems and software applications, also for the Mac OS X and Windows platforms, has been discovered recently by Russian programmer Maxim Andreev in the current stable builds of the software. It appears to let anyone with the necessary skills hack a computer to read local files on a remote machine and send them over the network using a specially crafted video file. Arch Linux devs already rebuilt their FFmpeg packages without the AppleHTTP and HLS demuxers.
Ffmpeg is used in some capacity in just about every video application I can think of. VLC, Kodi/XBMC, MythTV, Handbrake, Plex...
Eagles may soar, but weasels don't get sucked into jet engines.
Does ffmpegs fork have the bug as well?
Don't gentoo users choose their own build settings / features by default? What do you want the article to say? "Most gentoo users probably have the problem fixed by themselves already too but we don't really know?"
of millions of devleopers and users screaming in terror all at once...
I feel something terrible has happened...
Don't worry, Lennart is busy trying to absorb FFmpeg into systemd. Once there's some Poettering shitcode in FFmpeg, it'll cease to work at all and the vulnerability will have been neutralized.
This is news! A new critical zero-day vulnerability affecting millions of computers.
And here we thought drm free video files were safe.
Whelp another good reason to have a decent firewall.
Minimum threshold fixed. Thanks!
I have ffmpeg installed on Windows. I don't believe Windows uses it in any way, except when I launch it manually to convert a file. Am I still at risk (even when I don't choose to open a malicious file)?
Submitted by prisoninmate. Presumably he's in for crimes against the English language.
He's certainly familiar with really long sentences.
At the bottom of the
To the people who found this wide and deep issue. :)
Any news to who could be using the ability to create and track media files in the wild?
Time to alter the out going software firewall
Domestic spying is now "Benign Information Gathering"
Neither does Ubuntu, since everyone uses libav instead.
Media player classic on windows uses ffdshow which makes use of ffmpeg. Iirc mplayer also uses ffmpeg. But they are not the only ones a lot of video players rely on ffmpeg on the back end.
Minimum threshold fixed. Thanks!
You thought correctly.
Arch users can choose to build packages themselves using AUR that has multiple GUI/CLI frontends like yaourt or pacmanxg. but it's not a mess like debain apt-build and actually integrates well with the standard pacman system.
Moderating "-1, Disagree" is simple censorship. Have the guts to post your opinion. -- Spazmania (174582)
We use ffmpeg to process video files uploaded by customers. We'll be patching our app first thing in the morning. This is a big deal for us.
I have no problem with your religion until you decide it's reason to deprive others of the truth.
Libav seems to be reacting to this as well with a quick fix to blacklist HTTP in HLS. Whether the same vulnerability or a different one I don't know.
https://lists.libav.org/piperm...
https://en.wikipedia.org/wiki/Inverted_totalitarianism
By default Gentoo doesn't use FFMPEG, but the craptastic fork avlib. I wish that the developers of avlib many ills for ruining everything with their dman fork.
Right? With all these cores, world compiles quickly.
While Michael did resign as official leader, he is still very involved and seems to be defacto leader.
Watching the split was like watching a couple where you're friends with both going through a messy breakup. You can see both sides but don't want to take sides as they both have a point. In FFmpeg vs libav, it was mostly a conflict about the workflow. It was kind of disgusting how the (future) libav developers handled things, namely trying to hijack FFmpeg during the move to git.
https://en.wikipedia.org/wiki/Inverted_totalitarianism
instead of contacting developers he:
only then he contacted developers on 2016-01-13...