| ▲ | hekkle 3 hours ago | ||||||||||||||||
> and highly appreciated. Not by the maintainers it wasn't Mr. Google. | |||||||||||||||||
| ▲ | gpm 3 hours ago | parent [-] | ||||||||||||||||
Yes, but it was a public service not a service for the maintainers, and as a member of the public who like anyone who had run `ffmpeg -i <thing I downloaded from the internet>` was previously exposed to the vulnerability I highly appreciate their service. I'd highly appreciate even if the maintainers never did anything with the report, because in that case I would know to stop using ffmpeg on untrusted files. | |||||||||||||||||
| |||||||||||||||||