FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
References
Link | Resource |
---|---|
http://www.debian.org/security/2017/dsa-3957 | Third Party Advisory |
http://www.securityfocus.com/bid/99315 | Third Party Advisory VDB Entry |
https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021 | Issue Tracking Patch Third Party Advisory |
https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abb | Issue Tracking Patch Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html | Mailing List Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2017-06-28T06:00:00
Updated: 2019-01-08T10:57:01
Reserved: 2017-06-28T00:00:00
Link: CVE-2017-9993
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-06-28T06:29:00.520
Modified: 2019-03-26T17:56:24.007
Link: CVE-2017-9993
JSON object: View
Redhat Information
No data.
CWE