Security is the punch line for ffmpeg.
goddamn, and this is a project that prides itself on having had-written assembly in it
I couldn’t believe they had fallen for an April fools so hard.
I agree it reflects poorly on them though
Do you have an example?
That said, that dude has a point. "Researchers" chasing clout with their names attached to CVEs is kind of ridiculous. Half these CVEs are missing bounds checks that can be fixed with a patch in as much effort as writing up the blog post announcing that there was a missing bounds check.