logoalt Hacker News

bayouborneyesterday at 11:51 PM1 replyview on HN

What about VLC's own built-in versions of decoding libraries (I think, from the FFmpeg project)? Is there a scenario here where we may have to deal with malicious MP4 files?


Replies

jeffbeetoday at 12:51 AM

All media containers are potentially hostile. Any offset, extent, or reference has to be considered hostile user-provided input.