CVE-2017-9993 PUBLISHED

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.

EPSS 56.17% · 98.1th percentile

Risk Scores

EPSS Score
56.17%
98.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSffmpeg*, 0, 7:2.7.2-1build1
Ubuntu:Pro:14.04:LTSlibav0, 6:9.10-1ubuntu1, 6:9.10-1ubuntu2

Timeline

References

Open in Interactive Console →