CVE-2016-1897
Last modified
CVE-2016-1897 is a vulnerability of currently unknown severity. FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.. EPSS estimates a 14.62% chance of exploitation in the next 30 days.
Description
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | 2.0 |
| Ffmpeg | Ffmpeg | 2.0.1 |
| Ffmpeg | Ffmpeg | 2.0.2 |
| Ffmpeg | Ffmpeg | 2.0.3 |
| Ffmpeg | Ffmpeg | 2.0.4 |
| Ffmpeg | Ffmpeg | 2.0.5 |
| Ffmpeg | Ffmpeg | 2.0.6 |
| Ffmpeg | Ffmpeg | 2.0.7 |
| Ffmpeg | Ffmpeg | 2.1 |
| Ffmpeg | Ffmpeg | 2.1.1 |
| Ffmpeg | Ffmpeg | 2.1.2 |
| Ffmpeg | Ffmpeg | 2.1.3 |
| Ffmpeg | Ffmpeg | 2.1.4 |
| Ffmpeg | Ffmpeg | 2.1.5 |
| Ffmpeg | Ffmpeg | 2.1.6 |
| Ffmpeg | Ffmpeg | 2.1.7 |
| Ffmpeg | Ffmpeg | 2.1.8 |
| Ffmpeg | Ffmpeg | 2.2 |
| Ffmpeg | Ffmpeg | 2.2.1 |
| Ffmpeg | Ffmpeg | 2.2.2 |
| Ffmpeg | Ffmpeg | 2.2.3 |
| Ffmpeg | Ffmpeg | 2.2.4 |
| Ffmpeg | Ffmpeg | 2.2.5 |
| Ffmpeg | Ffmpeg | 2.2.6 |
| Ffmpeg | Ffmpeg | 2.2.7 |
| Ffmpeg | Ffmpeg | 2.2.8 |
| Ffmpeg | Ffmpeg | 2.2.9 |
| Ffmpeg | Ffmpeg | 2.2.10 |
| Ffmpeg | Ffmpeg | 2.2.11 |
| Ffmpeg | Ffmpeg | 2.2.12 |
| Ffmpeg | Ffmpeg | 2.2.13 |
| Ffmpeg | Ffmpeg | 2.2.14 |
| Ffmpeg | Ffmpeg | 2.2.15 |
| Ffmpeg | Ffmpeg | 2.2.16 |
| Ffmpeg | Ffmpeg | 2.3 |
| Ffmpeg | Ffmpeg | 2.3.1 |
| Ffmpeg | Ffmpeg | 2.3.2 |
| Ffmpeg | Ffmpeg | 2.3.3 |
| Ffmpeg | Ffmpeg | 2.3.4 |
| Ffmpeg | Ffmpeg | 2.3.5 |
| Ffmpeg | Ffmpeg | 2.3.6 |
| Ffmpeg | Ffmpeg | 2.4 |
| Ffmpeg | Ffmpeg | 2.4.1 |
| Ffmpeg | Ffmpeg | 2.4.2 |
| Ffmpeg | Ffmpeg | 2.4.3 |
| Ffmpeg | Ffmpeg | 2.4.4 |
| Ffmpeg | Ffmpeg | 2.4.5 |
| Ffmpeg | Ffmpeg | 2.4.6 |
| Ffmpeg | Ffmpeg | 2.4.7 |
| Ffmpeg | Ffmpeg | 2.4.8 |
Showing 50 of 83 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1897?
How severe is CVE-2016-1897?
How do I fix CVE-2016-1897?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-1887Integer signedness error in the sockargs function in sys/ker…
- CVE-2016-1888The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11…
- CVE-2016-1889Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10…
- CVE-2016-1894NetApp OnCommand Workflow Automation before 3.1P2 allows rem…
- CVE-2016-1895NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 all…
- CVE-2016-1896Race condition in the initialization process on Lexmark prin…
- CVE-2016-1898FFmpeg 2.x allows remote attackers to conduct cross-origin a…
- CVE-2016-1899CRLF injection vulnerability in the ui-blob handler in CGit …
- CVE-2016-1900CRLF injection vulnerability in the cgit_print_http_headers …
- CVE-2016-1901Integer overflow in the authenticate_post function in CGit b…
- CVE-2016-1902The nextBytes function in the SecureRandom class in Symfony …
- CVE-2016-1903The gdImageRotateInterpolated function in ext/gd/libgd/gd_in…
Are you affected by CVE-2016-1897?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
