logoalt Hacker News

bawolfflast Sunday at 8:42 PM2 repliesview on HN

Getting a polite bug report is not being harrased.


Replies

hitekkeryesterday at 1:49 AM

> This bug is subject to a 90-day disclosure deadline. If a fix for this issue is made available to users before the end of the 90-day deadline, this bug report will become public 30 days after the fix was made available. Otherwise, this bug report will become public at the deadline. The scheduled deadline is 2025-11-20 [https://issuetracker.google.com/issues/436510153]

Sounds like a threat to me. ffmpeg is a tiny team and Google is a goliath. Not to mention Google has used their AI to spam the same threat, about 8 times in the last few months https://ffmpeg.org/security.html

show 1 reply
x0x0last Sunday at 9:34 PM

Fix it or we publish exploit code is not far off.

show 2 replies