CVE-2016-1898

NameCVE-2016-1898
DescriptionFFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-3506-1
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)stretch7:3.2.10-1~deb9u1fixed
stretch (security)7:3.2.12-1~deb9u1fixed
buster, sid7:4.0.2-2fixed
libav (PTS)jessie (security), jessie6:11.12-1~deb8u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsource(unstable)7:2.8.5-1medium
ffmpegsourcesqueeze(unfixed)end-of-life
libavsource(unstable)(unfixed)medium
libavsourcejessie6:11.6-1~deb8u1mediumDSA-3506-1
libavsourcewheezy6:0.8.17-2mediumDSA-3506-1

Notes

[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
http://habrahabr.ru/company/mailru/blog/274855
Fixed in 2.8.5 upstream

Search for package or bug name: Reporting problems