CVE-2017-9993
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.4%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 16.44% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ffmpeg/ffmpeg · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2017/dsa-3957Third Party Advisory
- http://www.securityfocus.com/bid/99315Third Party Advisory, VDB Entry
- https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021Issue Tracking, Patch, Third Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abbIssue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2017/dsa-3957Third Party Advisory
- http://www.securityfocus.com/bid/99315Third Party Advisory, VDB Entry
- https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021Issue Tracking, Patch, Third Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abbIssue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlMailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.