themachinestops@lemmy.dbzer0.com to Technology@lemmy.worldEnglish · 19 hours agoAI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugsthehackernews.comexternal-linkmessage-square32linkfedilinkarrow-up1115arrow-down121
arrow-up194arrow-down1external-linkAI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugsthehackernews.comthemachinestops@lemmy.dbzer0.com to Technology@lemmy.worldEnglish · 19 hours agomessage-square32linkfedilink
minus-squareVibeSurgeon@piefed.sociallinkfedilinkEnglisharrow-up38arrow-down1·18 hours ago Its not like its a system service that you can get ingress through… With a competently crafted payload, you could perhaps get in via someone’s transcoding pipeline.
minus-squaregreyscale@lemmy.grey.ooolinkfedilinkEnglisharrow-up9arrow-down5·17 hours agoDoes nobody isolate ffmpeg and friends from their application? I can’t imagine you’d have much fun breaking into a container that terminates the moment the original ffmpeg stops, or over-runs its max execution time…
minus-square[object Object]@lemmy.calinkfedilinkEnglisharrow-up21arrow-down1·17 hours agoContainer escapes do exist, and they have shared kernel with the host
minus-squarePasserby6497@lemmy.worldlinkfedilinkEnglisharrow-up5·16 hours agoIf you’re running rootless containers, it’s less of a concern. I’m trying to move all of my public containers to podman for this reason
minus-squareVibeSurgeon@piefed.sociallinkfedilinkEnglisharrow-up1·10 hours agoSure, you’d need a second exploit to escalate from there. ffmpeg is expected to run for extended periods of time, given its use in transcoding.
With a competently crafted payload, you could perhaps get in via someone’s transcoding pipeline.
Does nobody isolate ffmpeg and friends from their application?
I can’t imagine you’d have much fun breaking into a container that terminates the moment the original ffmpeg stops, or over-runs its max execution time…
Container escapes do exist, and they have shared kernel with the host
If you’re running rootless containers, it’s less of a concern. I’m trying to move all of my public containers to podman for this reason
Sure, you’d need a second exploit to escalate from there.
ffmpeg is expected to run for extended periods of time, given its use in transcoding.