Comment on FFmpeg 9.0parentComments−beltsazar1moTo me the severity has nothing to do with how popular is a code path, but whether that code path is accessible to an attacker.That's true for targeted attacks. For untargeted attacks, attackers have little incentive to do the exploit.−cm21871moTargeted to what? ffmpeg? Ffmpeg is the OpenSSL of video transcoding, it is used absolutely everywhere. If there is a vulnerability in ffmpeg, any website that processes user supplied videos is vulnerable
Comments
That's true for targeted attacks. For untargeted attacks, attackers have little incentive to do the exploit.
Targeted to what? ffmpeg? Ffmpeg is the OpenSSL of video transcoding, it is used absolutely everywhere. If there is a vulnerability in ffmpeg, any website that processes user supplied videos is vulnerable