[FFmpeg-user] ffmpeg 4.4.1 security issue

Dama, Nikhil Nikhil.Dama at usaa.com
Thu Jan 6 15:12:51 EET 2022


Hi FFMPEG,

I am currently a data scientist at USAA. I was trying to use FFMPEG 4.4.1 to convert spex audio files to wav audio format.

My security team denied the download of the package, and here is the following explanation that they gave:
DOWNLOAD DENIED: Muliple known vulnerabilities like CVE-2021-38171
I was wondering how I can get this fixed or if it is already fixed in a later version? My security team is not allowing me to use the package until this issue is fixed.
I also wanted to know if there are any other python packages that I could use to convert spex files to wav files. I did not have any success in finding anything.

Here are the exact links that were provided to my security team:
Homepage URL: http://ffmpeg.org<https://urldefense.com/v3/__http:/ffmpeg.org__;!!GryZGb6B1VCs0SfC!SzJodt9OxlQVQEGaF_XaTKYWvWTckyzY-v-l8_KXU7bLkmvg-ZGGMGCw8k0iLJI$>
Download URL: https://ffmpeg.org/releases/ffmpeg-4.4.1.tar.xz<https://urldefense.com/v3/__https:/ffmpeg.org/releases/ffmpeg-4.4.1.tar.xz__;!!GryZGb6B1VCs0SfC!SzJodt9OxlQVQEGaF_XaTKYWvWTckyzY-v-l8_KXU7bLkmvg-ZGGMGCw9H1pc1o$>

Thanks,
Nikhil

Nikhil Dama | Data Scientist 1| Advanced Analytics and Machine Learning | USAA
nikhil.dama at usaa.com | Cell: (763) 528-0976



More information about the ffmpeg-user mailing list