FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
2017-06-28T06:29:00.520
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ffmpeg | ffmpeg | < 2.8.12 | Yes |
Application | ffmpeg | ffmpeg | < 3.1.9 | Yes |
Application | ffmpeg | ffmpeg | < 3.2.6 | Yes |
Application | ffmpeg | ffmpeg | < 3.3.2 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |