Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

TFA is about Project Zero getting uppity about an unexploitable non-issue in ffmpeg.

Project Zero hasn't reported any vulnerabilities in any software I maintain. Lots of other security groups have, some well respected as well, but to my knowledge none of these "outside" reports were actual vulnerabilities when analyzed in context.





You are welcome to view the report however you like, but a world where an easily reproducible OOB read and UAF in the default configuration is an "unexploitable non-issue" is not reality.

For a codec that isn't configured by default, and only used and maintained by a hobbyist video game content preservation group. Yeah it's a non-issue.

> a codec that isn't configured by default

Where did you get that idea?


It's used by exploit authors, too.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: