CVE-2016-1898

NameCVE-2016-1898
DescriptionFFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-3506-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)stretch (security)7:3.2.18-0+deb9u1fixed
stretch (lts), stretch7:3.2.19-0+deb9u5fixed
buster, buster (lts)7:4.1.11-0+deb10u2fixed
buster (security)7:4.1.11-0+deb10u1fixed
bullseye7:4.3.7-0+deb11u1fixed
bullseye (security)7:4.3.8-0+deb11u1fixed
bookworm (security), bookworm7:5.1.6-0+deb12u1fixed
sid, trixie7:7.1-3fixed
libav (PTS)jessie, jessie (lts)6:11.12-1~deb8u9fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsourcesqueeze(unfixed)end-of-life
ffmpegsource(unstable)7:2.8.5-1
libavsourcewheezy6:0.8.17-2DSA-3506-1
libavsourcejessie6:11.6-1~deb8u1DSA-3506-1
libavsource(unstable)(unfixed)

Notes

[squeeze] - ffmpeg <end-of-life> (Not supported in Squeeze LTS)
http://habrahabr.ru/company/mailru/blog/274855
Fixed in 2.8.5 upstream

Search for package or bug name: Reporting problems