| Vulnerability Name: | CVE-2017-9993 (CCN-127782) | ||||||||||||||||||||||||||||||||||||||||
| Assigned: | 2017-05-31 | ||||||||||||||||||||||||||||||||||||||||
| Published: | 2017-05-31 | ||||||||||||||||||||||||||||||||||||||||
| Updated: | 2019-03-26 | ||||||||||||||||||||||||||||||||||||||||
| Summary: | FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data. | ||||||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-9993 Source: DEBIAN Type: Third Party Advisory DSA-3957 Source: BID Type: Third Party Advisory, VDB Entry 99315 Source: CCN Type: BID-99315 FFmpeg CVE-2017-9993 Arbitrary File Read Vulnerability Source: XF Type: UNKNOWN ffmpeg-cve20179993-info-disc(127782) Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021 Source: CCN Type: FFmpeg GIT Repository avformat/avidec: Limit formats in gab2 to srt and ass/ssa Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abb Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20190107 [SECURITY] [DLA 1630-1] libav security update Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-9993 | ||||||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||||||