Hacker News new | ask | show | jobs
by fulafel 2984 days ago
I hope Ubuntu gets better at updating FFmpeg by bringing it in from the "universe" category of unsupported packages. Or second best option, stops shipping it.

Just this week there was an update showing that they had nearly a year-long window of vulnerability due to out of date version[1].

A media format christmas tree like this has really a lot of vulnerabilities & exposes the user to them fairly directly through media files.

[1] https://bugs.launchpad.net/ubuntu/+source/ffmpeg/+bug/169778...

1 comments

Seems like a good reason to keep it out of the base installation. Besides the patent minefield that comes with media players, of course.