FFmpeg의 보안 취약점인 PixelSmash가 발견되었습니다.
JFrog 보안 연구팀이 FFmpeg 미디어 프레임워크의 PixelSmash라는 취약점을 발견했습니다. 이 취약점은 원격 코드 실행 및 서비스 거부 공격을 가능하게 하며, 16년 동안 존재해왔습니다. MagicYUV 디코더를 사용하는 여러 응용 프로그램에 영향을 미치며, 악용에는 변조된 미디어 파일만 필요합니다. 사용자들은 해당 취약점을 확인하고 패치를 적용하거나 필요시 디코더를 비활성화할 것을 권장합니다.
A vulnerability named PixelSmash in FFmpeg has been discovered.
JFrog Security Research has revealed a vulnerability called PixelSmash in the FFmpeg media framework. This vulnerability allows for remote code execution and denial of service attacks, having existed for 16 years. It affects various applications using the MagicYUV decoder and can be exploited using just a crafted media file. Users are advised to check for the vulnerability and apply patches or disable the decoder as necessary.