top | item 28832163

(no title)

phit_ | 4 years ago

looks like Discord is vulnerable to this too, oopsie

discuss

order

LinuxBender|4 years ago

Not discord, but the default player is vulnerable to many different crash shenanigans. I get them sent to me all the time to look into and its usually just people using bogus timestamps, bogus seek times or concatenating multiple videos of different resolutions/rates that the player can't handle. If there was a way to get discord to spawn VLC for playing videos by default this would be less of a problem.

ronsor|4 years ago

> get discord to spawn VLC

So rather than loading the bogus videos in a sandboxed Chromium instance, you want to load them in an unsandboxed VLC instance? I smell eventual RCE.

jhgg|4 years ago

We don't transcode video, so no.

deathanatos|4 years ago

I presume you're Discord eng. You must do some sort of pass or parse of it, because every now and then I'll upload something and it will fail to process and result in what I'll call "the sad Discord poop"…

phit_|4 years ago

the player is malfunctioning anyway, similarly to those videos that report short runtime and then go on forever that get passed around quite frequently