High severity7.5NVD Advisory· Published Jun 28, 2017· Updated Jun 17, 2026
CVE-2017-9993
CVE-2017-9993
Description
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
5- github.com/FFmpeg/FFmpeg/commit/189ff4219644532bdfa7bab28dfedaee4d6d4021nvdIssue TrackingPatchThird Party Advisory
- github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abbnvdIssue TrackingPatchThird Party Advisory
- www.debian.org/security/2017/dsa-3957nvdThird Party Advisory
- www.securityfocus.com/bid/99315nvdThird Party AdvisoryVDB Entry
- lists.debian.org/debian-lts-announce/2019/01/msg00006.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.