FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-06-28T06:00:00

Updated: 2019-01-08T10:57:01

Reserved: 2017-06-28T00:00:00


Link: CVE-2017-9993

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-06-28T06:29:00.520

Modified: 2019-03-26T17:56:24.007


Link: CVE-2017-9993

JSON object: View

cve-icon Redhat Information

No data.

CWE