Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

decode video with libstagefright, which is a C++ library with vulnerabilities and insufficient sandboxing

Why? Why, if it is known to be a poorly written library, is it still part of an official release? And why the hell are client messages allow to specify the level of media down to the library linkage? Wtf.



The app is probably using MediaPlayer/MediaCodec and that uses stagefright under the covers.

The author is trying to build up hype for their vulnerability. Maybe if they shit on stagefright enough they can even start selling t-shirts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: