CVE-2016-1898

NameCVE-2016-1898
DescriptionFFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3506-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)stretch7:3.2.7-1~deb9u1fixed
stretch (security)7:3.2.8-1~deb9u1fixed
buster7:3.4-2fixed
sid7:3.4-3fixed
libav (PTS)wheezy6:0.8.17-2fixed
wheezy (security)6:0.8.21-0+deb7u1fixed
jessie6:11.9-1~deb8u1fixed
jessie (security)6:11.11-1~deb8u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsource(unstable)7:2.8.5-1medium
ffmpegsourcesqueeze(unfixed)end-of-life
libavsource(unstable)(unfixed)medium
libavsourcejessie6:11.6-1~deb8u1mediumDSA-3506-1
libavsourcewheezy6:0.8.17-2mediumDSA-3506-1

Notes

[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
http://habrahabr.ru/company/mailru/blog/274855
Fixed in 2.8.5 upstream

Search for package or bug name: Reporting problems