#pixelsmash

2 posts · Last used Jun 25

I find it weird calling the recent FFmpeg security vulnerability a RCE [1]. Where is that remote coming from? Yes sure, some web applications use FFmpeg and passes untrusted files to it. *Those* have a RCE. Setting the CVSS attack vector to "network" seems overinflating. By that standard any software that somebody built a webapp around is "network" facing. And let's not even talk about setting attack complexity to "low" but admitting that it only works with ASLR disabled. [1] https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ #FFmpeg #vulnerability #infosec #PixelSmash
36
6
23
2
🚨 ‼️ Pixelfed + Loops Admins PSA ⚠️ You need to update ffmpeg to v8.1.2+ ASAP. We made a guide for Ubuntu ⬇️ https://gist.github.com/dansup/460039bf77284752cbf5ca7d6406f6c4 Please boost for visibility, this also affects other fediverse software, and this guide may help those admins too. See https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ for more details about the vulnerability. #ffmpeg #pixelsmash
50
1
116
3
You've seen all posts