First published: Wed Jun 28 2017(Updated: )
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ffmpeg | 7:4.1.9-0+deb10u1 7:4.1.11-0+deb10u1 7:4.3.6-0+deb11u1 7:5.1.3-1 7:6.0-7 | |
FFmpeg | <2.8.12 | |
FFmpeg | >=3.0<3.1.9 | |
FFmpeg | >=3.2<3.2.6 | |
FFmpeg | >=3.3<3.3.2 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9993 is considered a high severity vulnerability due to its potential to allow unauthorized file access.
To mitigate CVE-2017-9993, update FFmpeg to versions 2.8.12, 3.1.9, 3.2.6, or 3.3.2 and later.
FFmpeg versions before 2.8.12, 3.0.x, 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 are affected by CVE-2017-9993.
CVE-2017-9993 allows attackers to read arbitrary files through crafted HTTP Live Streaming playlist data.
Yes, CVE-2017-9993 affects Debian users running vulnerable versions of FFmpeg.