Vulnerability Description
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | < 2.8.12 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.debian.org/security/2017/dsa-3957Third Party Advisory
- http://www.securityfocus.com/bid/99315Third Party AdvisoryVDB Entry
- https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021Issue TrackingPatchThird Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abbIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlMailing ListThird Party Advisory
- http://www.debian.org/security/2017/dsa-3957Third Party Advisory
- http://www.securityfocus.com/bid/99315Third Party AdvisoryVDB Entry
- https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021Issue TrackingPatchThird Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abbIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2017-9993?
CVE-2017-9993 is a vulnerability with a CVSS score of 7.5 (HIGH). FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attack...
How severe is CVE-2017-9993?
CVE-2017-9993 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9993?
Check the references section above for vendor advisories and patch information. Affected products include: Ffmpeg Ffmpeg, Debian Debian Linux.