logoalt Hacker News

joatmon-snoolast Saturday at 11:04 PM0 repliesview on HN

Google never asked a volunteer for a fix.

This is part of Google’s standard disclosure policy: it gets disclosed within 90 days starting from confirmation+contact.

If ffmpeg didn’t want to fix it, they could’ve just let the CVE get opened.