Skip to content

FFmpeg: Multiple vulnerabilities #67

@fsbruva

Description

@fsbruva

The bundled version of ffmpeg suffers from 286 known vulnerabilities, including 33 that received a severity rating of 10.0 (out of 10) from the NIST National Vulnerability Database.

Two options:

  1. Accept the risk, and continue to use ffmpeg 0.8.6
  2. Upgrade ffmpeg to latest version, 4.1.1 - which corrects all the vulnerabilities of 0.8.6.
  3. Upgrade to some other, intermediary version of ffmpeg

I recommend option 2. Version 4.1 only has 3 vulnerabilities reported, one of which was corrected by 4.4.1, and the other two were reported less than a week ago.

Which option should I pursue and prepare a PR for? I have already solved the upgraded ffmpeg API problems for libmediascan and libdlna, so that isn't a concern.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions