[Ffmpeg-devel] [Ffmpeg-devel-old] Re: Using ffmpeg libs in an OSS project is a nightmare

Dave Airlie airlied
Tue Aug 9 01:55:13 CEST 2005

> This is just as bad. The problem is that everyone is using old crap
> and reporting bugs in old crap. There's already a PERFECT solution
> that works for everyone who's doing it: include lavc with your project
> and static link it.

I think a lot of people are using old crap now,  how do security
related updates happen?

If I've got say mplayer, xine and some other ffmpeg using apps
installed, and ffmpeg has a security issue, I've got to go re-build
all of them from their own repostiories and hope that each project has
pulled in the security fix into their trees, chances are most of the
ffmpeg using projects don't stick to the top of ffmpeg CVS like glue
(I assume mplayer does)... they rebase their code from it every so
often when they feel they need to... in this way you are still having
a lot of people running "old crap" whether its statically linked old
crap or dynamic.... at least with dynamic there is chance everyone is
running the same old crap, and someone applying the security fix to
one will make it work for all ...


More information about the ffmpeg-devel mailing list