Skip to content

The dependency ffmpeg 4.3 has critical CVEs #4191

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
blzheng opened this issue Jul 2, 2021 · 5 comments
Closed

The dependency ffmpeg 4.3 has critical CVEs #4191

blzheng opened this issue Jul 2, 2021 · 5 comments

Comments

@blzheng
Copy link

blzheng commented Jul 2, 2021

🐛 Bug

In https://anaconda.org/pytorch/repo, the version of the dependency ffmpeg is 4.3, but ffmpeg 4.3 has several critical CVEs listed below. All those issues are related to buffer overflow with may cause unexpected application behavior.

CVE-2021-33815
CVE-2021-30123
CVE-2020-14212
CVE-2020-35965
CVE-2020-35964

BTW, ffmpeg 4.4 provides the most fixes. And I didn't find any strict restrictions on the version of ffmpeg in the source code. Could you update the ffmpeg from v4.3 to v4.4?

cc @ezyang @gchanan @zou3519 @bdhirsh @jbschlosser @anjali411 @fmassa @vfdev-5 @pmeier

@pmeier
Copy link
Collaborator

pmeier commented Jul 13, 2021

Cc @andfoy @bjuncek

@andfoy
Copy link
Contributor

andfoy commented Jul 13, 2021

Ffmpeg 4.3 cannot be used due to some major bugs. FFmpeg 4.4 has been already out during some months now, however it is not clear if we should package that version

@ezyang ezyang transferred this issue from pytorch/pytorch Jul 19, 2021
@bjuncek
Copy link
Contributor

bjuncek commented Jul 19, 2021

Should I test the new FFMPEG and plan for migration to it?
We've fixed incompatibilities with the deprecated API, and (providing no bugs) FBSync would be the biggest blocker. Any thoughts on this @fmassa @prabhat00155 ?

@bjuncek
Copy link
Contributor

bjuncek commented Jul 30, 2021

also note that conda's ffmpeg-feedstock is still at 4.3.1 by default

@bjuncek
Copy link
Contributor

bjuncek commented Apr 1, 2022

FFMPEG in conda-forge has been updated, and we've finished the migration (#5644 ) so I'm closing this

@bjuncek bjuncek closed this as completed Apr 1, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants