-
Notifications
You must be signed in to change notification settings - Fork 74
Open
Description
The bundled version of ffmpeg suffers from 286 known vulnerabilities, including 33 that received a severity rating of 10.0 (out of 10) from the NIST National Vulnerability Database.
Two options:
- Accept the risk, and continue to use ffmpeg 0.8.6
- Upgrade ffmpeg to latest version, 4.1.1 - which corrects all the vulnerabilities of 0.8.6.
- Upgrade to some other, intermediary version of ffmpeg
I recommend option 2. Version 4.1 only has 3 vulnerabilities reported, one of which was corrected by 4.4.1, and the other two were reported less than a week ago.
Which option should I pursue and prepare a PR for? I have already solved the upgraded ffmpeg API problems for libmediascan and libdlna, so that isn't a concern.
Metadata
Metadata
Assignees
Labels
No labels