All errata/sisyphus/ALT-PU-2017-1725-1
ALT-PU-2017-1725-1

Package update ffmpeg in branch sisyphus

Version3.3.2-alt1
Published2017-06-14
Max severityHIGH
Severity:

Closed issues (1)

CVE-2017-9993
HIGH7.5

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.

Published: 2017-06-28Modified: 2025-04-20
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N