CVE-2016-1897

NameCVE-2016-1897
DescriptionFFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-3506-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)buster7:4.1.9-0+deb10u1fixed
buster (security)7:4.1.11-0+deb10u1fixed
bullseye (security), bullseye7:4.3.6-0+deb11u1fixed
bookworm, bookworm (security)7:5.1.4-0+deb12u1fixed
trixie7:6.1.1-1fixed
sid7:6.1.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsourcesqueeze(unfixed)end-of-life
ffmpegsource(unstable)7:2.8.5-1
libavsourcewheezy6:0.8.17-2DSA-3506-1
libavsourcejessie6:11.6-1~deb8u1DSA-3506-1
libavsource(unstable)(unfixed)

Notes

[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
http://habrahabr.ru/company/mailru/blog/274855
Fixed in 2.8.5 upstream

Search for package or bug name: Reporting problems