CVE-2017-9993
Summary
| CVE | CVE-2017-9993 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-28 06:29:00 UTC |
| Updated | 2019-03-26 17:56:00 UTC |
| Description | FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Ffmpeg | Ffmpeg | All | All | All | All |
| Application | Ffmpeg | Ffmpeg | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| FFmpeg CVE-2017-9993 Arbitrary File Read Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-3957-1 ffmpeg | DEBIAN | www.debian.org | Third Party Advisory |
| avformat/avidec: Limit formats in gab2 to srt and ass/ssa · FFmpeg/FFmpeg@a5d849b · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| avformat/hls: Check local file extensions · FFmpeg/FFmpeg@189ff42 · GitHub | MISC | github.com | Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] [DLA 1630-1] libav security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.