#pixelsmash

2 posts · Last used Jun 25

Back to Timeline
faker @faker@infosec.exchange · Jun 25, 2026
I find it weird calling the recent FFmpeg security vulnerability a RCE [1]. Where is that remote coming from? Yes sure, some web applications use FFmpeg and passes untrusted files to it. *Those* have a RCE. Setting the CVSS attack vector to "network" seems overinflating. By that standard any software that somebody built a webapp around is "network" facing. And let's not even talk about setting attack complexity to "low" but admitting that it only works with ASLR disabled. [1] https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ #FFmpeg #vulnerability #infosec #PixelSmash
4
0
3
pixelfed @pixelfed@mastodon.social · Jun 25, 2026
Boosted by Furbland's Very Cool Account™ @GroupNebula563@mastodon.social
🚨 ‼️ Pixelfed + Loops Admins PSA ⚠️ You need to update ffmpeg to v8.1.2+ ASAP. We made a guide for Ubuntu ⬇️ https://gist.github.com/dansup/460039bf77284752cbf5ca7d6406f6c4 Please boost for visibility, this also affects other fediverse software, and this guide may help those admins too. See https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ for more details about the vulnerability. #ffmpeg #pixelsmash
9
0
37

You've seen all posts