Furthermore, Secunia doesn't seem to realize that VLC doesn't do static linking on all platforms (lol) -- I mean, why even go after VLC? This was clearly an ffmpeg problem. What a bunch of amateurs.
Furthermore, Secunia doesn't seem to realize that VLC doesn't do static linking on all platforms (lol) -- I mean, why even go after VLC? This was clearly an ffmpeg problem. What a bunch of amateurs.
If your customer gets it from you, then it is your responsibility.
Edit: To clarify, from what I can tell no one has ever paid even a cent for VLC, though they may have donated to the VideoLAN project.
And regardless of whether you feel that they had any moral responsibility to fix the vulnerability anyway, it's hard to fault VideoLAN here since that is exactly what they did (unless you believe Secunia's side of the story, of course).
Like I said, the status quo has always been to delegate third-party vulnerabilities or bugs (especially if statically linked) to their respective vendors. The people from VLC were gentlemen for fixing the problem themselves and then upstreaming. I doubt many would disagree.
However, their blog post makes no mention of that, and they don't seem to question the link between vulnerability PR and actual, verifiable vulnerabilities.