| ▲ | thinkingtoilet 2 hours ago | |||||||
It's all about time in the day, my friend. Do you want to secure a feature used by 100% of your users or 0.01% of your users? Which has a better ROI? | ||||||||
| ▲ | HelloNurse an hour ago | parent | next [-] | |||||||
Given that it is easy to feed FFMPEG arbitrary input to exploit any vulnerability, popular codecs are very likely to be already secure enough, while unpopular ones are far more dangerous and deserve more attention. It can be assumed that an attacker would target the worst, easiest to exploit codec they can find in the whole of FFMPEG. | ||||||||
| ▲ | jobigoud an hour ago | parent | prev [-] | |||||||
It's used by most users, that's what they are saying, it doesn't matter that the file format is obscure. If you make a video player based on ffmpeg you take input videos. The attacker can share a specially crafted video with the victim. Same kind of attack as sharing word documents. | ||||||||
| ||||||||