Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9993

Опубликовано: 28 июн. 2017
Источник: debian
EPSS Средний

Описание

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegfixed7:3.2.6-1package
libavremovedpackage

Примечания

  • https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021

  • https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abb

  • Fixed in 3.2.6

  • Jessie is only partially affected. Only the second commit is

  • relevant. HTTP Live Streaming filename extension code is not present.

EPSS

Процентиль: 97%
0.16437
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.

CVSS3: 7.5
nvd
около 9 лет назад

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.

CVSS3: 7.5
github
больше 4 лет назад

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.

EPSS

Процентиль: 97%
0.16437
Средний