maintainer-feedback requested: [Bug 215271] www/chromium: maybe use system ffmpeg

bugzilla-noreply at freebsd.org bugzilla-noreply at freebsd.org
Tue Dec 13 08:48:46 UTC 2016


Jan Beich (mail not working) <jbeich at FreeBSD.org> has reassigned Bugzilla
Automation <bugzilla at FreeBSD.org>'s request for maintainer-feedback to
chromium at FreeBSD.org:
Bug 215271: www/chromium: maybe use system ffmpeg
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=215271



--- Description ---
Chromium bundles out of date FFmpeg snapshot. While upstream limits the attack
surface to what's defined in HTML5 video/audio + WebRTC and backports security
fixes, some may fly under the radar e.g.,

    CVE-2016-6164 is still unfixed as of 55.0.2883.87:
    https://git.ffmpeg.org/gitweb/ffmpeg.git/commitdiff/054db631200c


More information about the freebsd-chromium mailing list