I find it weird calling the recent FFmpeg security vulnerability a RCE [1]. Where is that remote coming from?
Yes sure, some web applications use FFmpeg and passes untrusted files to it. *Those* have a RCE.
Setting the CVSS attack vector to "network" seems overinflating.
By that standard any software that somebody built a webapp around is "network" facing.
And let's not even talk about setting attack complexity to "low" but admitting that it only works with ASLR disabled.
[1] https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/
#FFmpeg #vulnerability #infosec #PixelSmash
pixelfed
@pixelfed@mastodon.social
Ad-Free Photo Sharing. iOS: https://apps.apple.com/us/app/pixelfed/id1632519816 Android: https://play.google.com/store/apps/details?id=com.pixelfed F-Droid: https://fdroid.pixelfed.net/fdroid/repo/ Smile 😁 #pixelfed #fedi22 Discord: https://discord.gg/VDhM32hbUK Matrix: https://matrix.to/#/#pixeldev:matrix.org
mastodon.social
🚨 ‼️ Pixelfed + Loops Admins PSA ⚠️
You need to update ffmpeg to v8.1.2+ ASAP.
We made a guide for Ubuntu ⬇️
https://gist.github.com/dansup/460039bf77284752cbf5ca7d6406f6c4
Please boost for visibility, this also affects other fediverse software, and this guide may help those admins too.
See https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ for more details about the vulnerability.
#ffmpeg #pixelsmash
You've seen all posts