CVE-2017-9993
Last modified
CVE-2017-9993 is a vulnerability of currently unknown severity. FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.. EPSS estimates a 16.44% chance of exploitation in the next 30 days.
Description
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | < 2.8.12 |
| Ffmpeg | Ffmpeg | >= 3.0, < 3.1.9 |
| Ffmpeg | Ffmpeg | >= 3.2, < 3.2.6 |
| Ffmpeg | Ffmpeg | >= 3.3, < 3.3.2 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
References
- http://www.debian.org/security/2017/dsa-3957Third Party Advisory
- http://www.securityfocus.com/bid/99315Third Party Advisory, VDB Entry
- https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021Issue Tracking, Patch, Third Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abbIssue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2017/dsa-3957Third Party Advisory
- http://www.securityfocus.com/bid/99315Third Party Advisory, VDB Entry
- https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021Issue Tracking, Patch, Third Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abbIssue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9993?
How severe is CVE-2017-9993?
How do I fix CVE-2017-9993?
Are you affected by CVE-2017-9993?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
