Ubuntu's current LTS version (24.04) contains ffmpeg version 7:6.1.1-3ubuntu5 which has this buffer overflow vulnerability:

https://trac.ffmpeg.org/ticket/10952

https://ubuntu.com/security/CVE-2024-32230

On my only Ubuntu computer, my update widget says that I need to upgrade to ffmpeg version 7:6.1.1-3ubuntu5+esm2 but can only only do so with Ubuntu Pro. I'm not eligible for Ubuntu Pro.

Ubuntu claims that 24.04 is currently fully supported, and should have complete security updates. However, they seem to have paywalled this security update.

What should I do?

you are viewing a single comment's thread
view the rest of the comments
[–] 0 points 2 years ago (3 children)

However, Ubuntu started a service called Ubuntu Pro / ESM that provides updates for packages in universe.

Since it's all free software, what gives Ubuntu the privilege to restrict these updates behind paywalls and signups?

Pro is also free for personal use on up to 5 machines, so there’s no reason not to enable it.

Fuck that bullshit. We shouldn't be encouraging or enabling this behavior at all.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 17 points 2 years ago* (1 child)

    GPL does not restrict you from selling the software, though you can't stop getting distributed by someone who bought it. Even RMS himself sold Emacs back in the day.

    EDIT: I'm not saying it's justified in moral sense, I think it sucks ass. But it's not against the license.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -2 points 2 years ago (1 child)

    GPL does not restrict you from selling the software

    Oh god, we know.

    Practically speaking though, if anyone can redistribute it for free then it's available for free.

  • source
  • parent
  • hideshow 2 child comments