![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2017-9993 |
Description: | FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.703957 1.3.6.1.4.1.25623.1.0.891630 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2017-9993 BugTraq ID: 99315 http://www.securityfocus.com/bid/99315 Debian Security Information: DSA-3957 (Google Search) http://www.debian.org/security/2017/dsa-3957 https://github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021 https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abb https://lists.debian.org/debian-lts-announce/2019/01/msg00006.html |