First published: Fri Dec 27 2024(Updated: )
A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
FFmpeg | >=2.0<6.0 | |
FFmpeg | >=3.0<5.0 | |
FFmpeg | >=4.2<6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6605 is classified as a moderate severity vulnerability due to its ability to allow arbitrary HTTP GET requests.
To mitigate CVE-2023-6605, upgrade to a patched version of FFmpeg that addresses the identified flaw.
CVE-2023-6605 affects FFmpeg versions from 2.0 up to but not including 6.0.
CVE-2023-6605 allows for crafted DASH playlists to execute arbitrary HTTP GET requests on the host machine.
If you are using FFmpeg version between 2.0 and 6.0, your installation is vulnerable to CVE-2023-6605.