[FFmpeg-devel] [PATCH] Dynamic plugins loading

Luca Barbato lu_zero
Tue Nov 2 22:00:58 CET 2010


On 11/2/10 8:22 PM, Felipe Contreras wrote:
> On Tue, Nov 2, 2010 at 3:30 PM, Luca Barbato<lu_zero at gentoo.org>  wrote:
>> On 11/2/10 12:21 PM, Ronald S. Bultje wrote:
>>>
>>> In the real world, if installing a new application ("ConvertYtoCVC")
>>> with a custom codec causes my Chrome to suddenly crash and become
>>> exploitable, we are in deep PR shit. There is no way to save ourselves
>>> from that mess.
>>
>> In the real world having your application replacing libavcodec or an other
>> system lib is bad nonetheless.
>
> Chrome doesn't use the system's FFmpeg, it has it's own built-in
> protected in a sandbox. They would build it with this option disabled.
> Not relevant.

Chrome isn't the point. The point is having an application messing with 
system libraries.

lu



More information about the ffmpeg-devel mailing list