CVE-2017-9993
Last modified
CVE-2017-9993 is a vulnerability of currently unknown severity. FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.. EPSS estimates a 16.44% chance of exploitation in the next 30 days.
Description
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | < 2.8.12 |
| Ffmpeg | Ffmpeg | >= 3.0, < 3.1.9 |
| Ffmpeg | Ffmpeg | >= 3.2, < 3.2.6 |
| Ffmpeg | Ffmpeg | >= 3.3, < 3.3.2 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
References
- http://www.debian.org/security/2017/dsa-3957Third Party Advisory
- http://www.securityfocus.com/bid/99315Third Party Advisory, VDB Entry
- https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021Issue Tracking, Patch, Third Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abbIssue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlMailing List, Third Party Advisory
- http://www.debian.org/security/2017/dsa-3957Third Party Advisory
- http://www.securityfocus.com/bid/99315Third Party Advisory, VDB Entry
- https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021Issue Tracking, Patch, Third Party Advisory
- https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abbIssue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9993?
How severe is CVE-2017-9993?
How do I fix CVE-2017-9993?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-9987There is a heap-based buffer overflow in the function hpel_m…
- CVE-2017-9988The readEncUInt30 function in util/read.c in libming 0.4.8 m…
- CVE-2017-9989util/outputtxt.c in libming 0.4.8 mishandles memory allocati…
- CVE-2017-9990Stack-based buffer overflow in the color_string_to_rgba func…
- CVE-2017-9991Heap-based buffer overflow in the xwd_decode_frame function …
- CVE-2017-9992Heap-based buffer overflow in the decode_dds1 function in li…
- CVE-2017-9994libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.…
- CVE-2017-9995libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not proper…
- CVE-2017-9996The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpe…
- CVE-2017-9998The _dwarf_decode_s_leb128_chk function in dwarf_leb.c in li…6.5
- CVE-2017-9999Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2017-9993?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
