Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-1898


FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.


Published

2016-01-15T03:59:23.923

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ffmpeg ffmpeg 2.0 Yes
Application ffmpeg ffmpeg 2.0.1 Yes
Application ffmpeg ffmpeg 2.0.2 Yes
Application ffmpeg ffmpeg 2.0.3 Yes
Application ffmpeg ffmpeg 2.0.4 Yes
Application ffmpeg ffmpeg 2.0.5 Yes
Application ffmpeg ffmpeg 2.0.6 Yes
Application ffmpeg ffmpeg 2.0.7 Yes
Application ffmpeg ffmpeg 2.1 Yes
Application ffmpeg ffmpeg 2.1.1 Yes
Application ffmpeg ffmpeg 2.1.2 Yes
Application ffmpeg ffmpeg 2.1.3 Yes
Application ffmpeg ffmpeg 2.1.4 Yes
Application ffmpeg ffmpeg 2.1.5 Yes
Application ffmpeg ffmpeg 2.1.6 Yes
Application ffmpeg ffmpeg 2.1.7 Yes
Application ffmpeg ffmpeg 2.1.8 Yes
Application ffmpeg ffmpeg 2.2 Yes
Application ffmpeg ffmpeg 2.2.1 Yes
Application ffmpeg ffmpeg 2.2.2 Yes
Application ffmpeg ffmpeg 2.2.3 Yes
Application ffmpeg ffmpeg 2.2.4 Yes
Application ffmpeg ffmpeg 2.2.5 Yes
Application ffmpeg ffmpeg 2.2.6 Yes
Application ffmpeg ffmpeg 2.2.7 Yes
Application ffmpeg ffmpeg 2.2.8 Yes
Application ffmpeg ffmpeg 2.2.9 Yes
Application ffmpeg ffmpeg 2.2.10 Yes
Application ffmpeg ffmpeg 2.2.11 Yes
Application ffmpeg ffmpeg 2.2.12 Yes
Application ffmpeg ffmpeg 2.2.13 Yes
Application ffmpeg ffmpeg 2.2.14 Yes
Application ffmpeg ffmpeg 2.2.15 Yes
Application ffmpeg ffmpeg 2.2.16 Yes
Application ffmpeg ffmpeg 2.3 Yes
Application ffmpeg ffmpeg 2.3.1 Yes
Application ffmpeg ffmpeg 2.3.2 Yes
Application ffmpeg ffmpeg 2.3.3 Yes
Application ffmpeg ffmpeg 2.3.4 Yes
Application ffmpeg ffmpeg 2.3.5 Yes
Application ffmpeg ffmpeg 2.3.6 Yes
Application ffmpeg ffmpeg 2.4 Yes
Application ffmpeg ffmpeg 2.4.1 Yes
Application ffmpeg ffmpeg 2.4.2 Yes
Application ffmpeg ffmpeg 2.4.3 Yes
Application ffmpeg ffmpeg 2.4.4 Yes
Application ffmpeg ffmpeg 2.4.5 Yes
Application ffmpeg ffmpeg 2.4.6 Yes
Application ffmpeg ffmpeg 2.4.7 Yes
Application ffmpeg ffmpeg 2.4.8 Yes
Application ffmpeg ffmpeg 2.4.9 Yes
Application ffmpeg ffmpeg 2.4.10 Yes
Application ffmpeg ffmpeg 2.4.11 Yes
Application ffmpeg ffmpeg 2.4.12 Yes
Application ffmpeg ffmpeg 2.5 Yes
Application ffmpeg ffmpeg 2.5.1 Yes
Application ffmpeg ffmpeg 2.5.2 Yes
Application ffmpeg ffmpeg 2.5.3 Yes
Application ffmpeg ffmpeg 2.5.4 Yes
Application ffmpeg ffmpeg 2.5.5 Yes
Application ffmpeg ffmpeg 2.5.6 Yes
Application ffmpeg ffmpeg 2.5.7 Yes
Application ffmpeg ffmpeg 2.5.8 Yes
Application ffmpeg ffmpeg 2.5.9 Yes
Application ffmpeg ffmpeg 2.6 Yes
Application ffmpeg ffmpeg 2.6.1 Yes
Application ffmpeg ffmpeg 2.6.2 Yes
Application ffmpeg ffmpeg 2.6.3 Yes
Application ffmpeg ffmpeg 2.6.4 Yes
Application ffmpeg ffmpeg 2.6.5 Yes
Application ffmpeg ffmpeg 2.6.6 Yes
Application ffmpeg ffmpeg 2.7 Yes
Application ffmpeg ffmpeg 2.7.1 Yes
Application ffmpeg ffmpeg 2.7.2 Yes
Application ffmpeg ffmpeg 2.7.3 Yes
Application ffmpeg ffmpeg 2.7.4 Yes
Application ffmpeg ffmpeg 2.8 Yes
Application ffmpeg ffmpeg 2.8 Yes
Application ffmpeg ffmpeg 2.8.1 Yes
Application ffmpeg ffmpeg 2.8.2 Yes
Application ffmpeg ffmpeg 2.8.3 Yes
Application ffmpeg ffmpeg 2.8.4 Yes
Operating System canonical ubuntu_linux 12.04 Yes
Operating System opensuse leap 42.1 Yes

References