Anyway....interesting debate about statically linked libraries. Seems like the original vulnerability was in ffmpeg (vlc statically links to it). So in this case what should/can videolan do ?
Anyway....interesting debate about statically linked libraries. Seems like the original vulnerability was in ffmpeg (vlc statically links to it). So in this case what should/can videolan do ?
As such, it's VLC responsibility to not ship a product that may harm a user's computer, even if the error is not in their code.
To give you a similar example, have a look at this post about the impact of vulnerabilities in third party libraries on commercial forensic products[1].
I would suspect that expert witnesses relying on this could have a case argued against them in court regarding the integrity of the application data and their processes if they're not prepared.
[1] - https://www.cert.org/blogs/certcc/2013/07/forensics_software...
All the vulnerabilities have been fixed. Which one are you referring to?
> Seems like the original vulnerability was in ffmpeg (vlc statically links to it). So in this case what should/can videolan do ?
I responded to the question. But to answer yours:
> Which one are you referring to?
Specifically the ffmpeg bug that Secunia reported that you claimed to fix, which wasn't quite correctly fixed, when you decided to go and stir up drama on the Internet and threaten Secunia with lawyers you don't have and can't afford.
That one.
And that it's fixed now is irrelevant. You made a dick move by threatening legal action without having anything to back it up and it's cost you a lot of goodwill no doubt by stirring it up.
Thus far Secunia has done neither.