CVE-2016-1897

NameCVE-2016-1897
DescriptionFFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3506-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)stretch (security), stretch7:3.2.9-1~deb9u1fixed
buster7:3.4-4fixed
sid7:3.4.1-1fixed
libav (PTS)wheezy6:0.8.17-2fixed
wheezy (security)6:0.8.21-0+deb7u1fixed
jessie (security), jessie6:11.11-1~deb8u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsource(unstable)7:2.8.5-1medium
ffmpegsourcesqueeze(unfixed)end-of-life
libavsource(unstable)(unfixed)medium
libavsourcejessie6:11.6-1~deb8u1mediumDSA-3506-1
libavsourcewheezy6:0.8.17-2mediumDSA-3506-1

Notes

[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
http://habrahabr.ru/company/mailru/blog/274855
Fixed in 2.8.5 upstream

Search for package or bug name: Reporting problems