[arch-dev-public] FFmpeg vulnerability
alucryd at archlinux.org
Fri Jan 15 19:47:41 UTC 2016
On Wed, Jan 13, 2016 at 7:24 PM, Maxime Gauduin <alucryd at archlinux.org>
> Hi all,
> A vulnerability via which someone can steal files from remote machines has
> been discovered in FFmpeg and was made public. See associated bug report
> Disabling networking altogether seems a bit much, but James Darnley @
> FFmpeg suggested that disabling HLS should do the trick until a fix is
> committed so I'll go ahead and rebuild our FFmpeg without the HLS and
> AppleHTTP demuxers.
>  https://bugs.archlinux.org/task/47738
> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail> This
> email has been sent from a virus-free computer protected by Avast.
The vulnerabilty is now fixed upstream, I just pushed 1:2.8.4-4 built with
the 3 relevant patches.
More information about the arch-dev-public