Information disclosure in FFmpeg - CVE-2017-9993
Published: June 28, 2017 / Updated: July 18, 2020
FFmpeg
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
How to mitigate CVE-2017-9993
Sources
- http://www.debian.org/security/2017/dsa-3957
- http://www.securityfocus.com/bid/99315
- https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021
- https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abb
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html