CVE-2017-9993

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:37

Type Values Removed Values Added
References () http://www.debian.org/security/2017/dsa-3957 - Third Party Advisory () http://www.debian.org/security/2017/dsa-3957 - Third Party Advisory
References () http://www.securityfocus.com/bid/99315 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/99315 - Third Party Advisory, VDB Entry
References () https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021 - Issue Tracking, Patch, Third Party Advisory () https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021 - Issue Tracking, Patch, Third Party Advisory
References () https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abb - Issue Tracking, Patch, Third Party Advisory () https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abb - Issue Tracking, Patch, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html - Mailing List, Third Party Advisory

Information

Published : 2017-06-28 06:29

Updated : 2024-11-21 03:37


NVD link : CVE-2017-9993

Mitre link : CVE-2017-9993

CVE.ORG link : CVE-2017-9993


JSON object : View

Products Affected

debian

  • debian_linux

ffmpeg

  • ffmpeg
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor