Bug#729203: Packaging for FFmpeg avoiding conflicts with libav
- To: Michael Niedermayer <michaelni@gmx.at>
- Cc: 729203@bugs.debian.org, Andreas Cadhalpun <andreas.cadhalpun@googlemail.com>, Adrian Bunk <bunk@stusta.de>, Antoine Beaupré <anarcat@debian.org>, Rogério Brito <rbrito@ime.usp.br>, Jackson Doak <noskcaj@ubuntu.com>, team@security.debian.org, Timothy Gu <timothygu99@gmail.com>, Jonathan Dowland <jmtd@debian.org>
- Subject: Bug#729203: Packaging for FFmpeg avoiding conflicts with libav
- From: Moritz Mühlenhoff <jmm@inutil.org>
- Date: Wed, 26 Feb 2014 16:49:09 +0100
- Message-id: <[🔎] 20140226154909.GF4558@pisco.westfalen.local>
- Reply-to: Moritz Mühlenhoff <jmm@inutil.org>, 729203@bugs.debian.org
- In-reply-to: <[🔎] 20140226013047.GN9836@nb4>
- References: <[🔎] 20140223095318.GA3141@pisco.westfalen.local> <[🔎] 20140223104834.GA11041@bunk.dyndns.info> <[🔎] 20140223215636.GA3103@pisco.westfalen.local> <[🔎] 530A77F4.2050102@googlemail.com> <[🔎] 20140225165702.GA2960@pisco.westfalen.local> <[🔎] 530CD188.30100@googlemail.com> <[🔎] 20140225211843.GB18555@scapa.corsac.net> <[🔎] 530D1981.1050402@googlemail.com> <[🔎] 20140225223333.GA19573@inutil.org> <[🔎] 20140226013047.GN9836@nb4>
On Wed, Feb 26, 2014 at 02:30:47AM +0100, Michael Niedermayer wrote:
> > Yes, it's the latter: I didn't badmouth ffmpeg in any way: it was said that libav
> > fixed less Google fuzzer samples than libav; for which I added my observation that when
> > I looked at several CVE assignments for ffmpeg fixes the affected code
> > didn't exist in libav releases and that explains the difference in numbers.
> > That doesn't mean that ffmpeg is worse than libav, it simply means that the
> > code has diverged and different code is affected.
>
> I belive maybe some things are a bit mixed up here
> The "less fixes in libav" stuff was AFAIK a comparission between the
> libav and ffmpeg git master branches
I'm referring to issues listed on ffmpeg.org/security for which I checked
the applicability to libav as in Debian. One thing I remember was the
g2meet codec which wasn't in any libav branch in Debian.
Anyway, I don't have time to discuss this in depth.
Cheers,
Moritz
Reply to: