CVE-2016-1897
Published Jan 15, 2016
Last updated 6 years ago
Overview
- Description
- FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1337F5B-E9D9-4335-9E05-50018E59E530" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B27C609-E4B4-41CD-B228-38267AA3A8AB" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C97DBEE2-AF4E-4C2D-A185-F2A1B965D9DA" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDEDAA24-D9E0-4384-B193-0C8814E4FDD6" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "40B0C71E-341A-434A-90AE-326097AC85E4" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E83D73FF-E6F6-4399-B721-6C6275C52B55" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B07481C8-7CEB-4B81-B8E0-FF45DAA28870" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9E69881-F5C7-4BB3-8BEB-C3C85CCD4B93" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B70C00A9-3562-45AB-B494-3BA91B6AFC3E" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A30389D2-2873-4F15-B249-066B6D37AC23" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0487928D-6630-4E23-BBA5-BED0A0F156B1" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C3088131-C48D-463B-8709-78A90EDE1FA4" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.1.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DADF01E6-CB58-4593-B444-A59232EE83CB" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "06442F70-22B4-49E5-B25B-92E03973B57E" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E8FDCEA-336D-4BC9-AE93-9A0CCE443AC8" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B5505E58-DF70-4408-A347-FBB74D119566" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D406D9D-A51A-4EE6-88BF-279422A4DBA4" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B08A7BE-7C98-4659-808F-86A8EB4676D2" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4BF38DD1-2604-41AD-975A-56CC24767799" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C76392F6-6992-4B67-97BA-607A091DDA6B" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB396E84-FE69-4E19-9937-B82A63D347AF" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CE9CF7C7-3730-43EC-B63E-B004D979E57A" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "889B2130-CB88-487B-92FB-959DB44B8E34" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9BE4879-972C-45EA-8253-46E5BE98FFA9" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "653411BA-9F0B-4BFC-8A42-6576E956F96D" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "268DAF2F-4484-4212-AEB0-F9A10596F874" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BCD7A424-DA4D-4508-B4EB-14A1BA65E596" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C190A7C8-2DAE-4F72-A620-9D184CBF10B1" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E8764DC-1C01-4C3E-A7AC-C8AF69F944E1" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7A45FBF-A89E-4F1C-B397-AB2A53DB805C" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78B3B781-7DEC-475C-A429-11D1B2F69CD2" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1FDCCDDC-6CDA-4D3B-BB4C-C370C69EB1C9" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63209CD1-2710-462C-9AEC-A9DE2B41A7B1" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.2.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "336CB8D4-EBE0-4E34-9F71-DD0FEA8A99C3" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "207DF654-326E-43A9-A5EC-BC239BF30422" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8794F8C5-A639-4C89-8C51-87787B29833F" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5B50AB2A-FA23-4BB0-AA21-724E770ADEFB" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "94BC4C82-371C-4B80-A615-AE0F15F1D6CA" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0E114D7-1323-4965-9680-8638ACDFF20B" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7BBF39F-668E-4771-99A0-F008B18B03F5" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CC929DD-566D-4906-8960-7BCFA7EE0384" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C3E41754-D2AB-4DE1-9ED9-A88F5E28ABFF" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "14D1738D-D85A-4650-9DAB-C626E7F52812" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A91B8DD5-FB80-47E7-8AF3-57D72CD4D034" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1ADB969-FA62-4238-83DF-D5703603A9FE" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D51D915-0FAF-449F-825B-1F2B1F9BAF00" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19772D67-FAE5-4178-815D-4F511AE0411E" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A6097F4-A8D1-4070-A4B2-8479421C15DB" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8BBBBB2E-F454-44F7-8131-BFF852BC6DE0" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE75C995-BCB6-4F46-AE8C-B86FBF2702E3" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "291E07BD-70C0-403B-ACB3-B49D2DED59C8" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FA5BAC2-C23B-4D4E-8CA1-57780761AC35" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B0AE997C-54E3-4619-A269-E96E79164C0A" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.4.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7D13C0AC-8AB4-49E1-8A5C-98DCA6F01D08" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F19A0139-AF47-434F-AFE9-ECC003675537" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF38E5B7-AB89-418E-B507-3D660FE753C4" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5249D4A-D8D9-4B89-96B6-E957A2210750" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29619AAD-6792-4B38-8DFB-706BEACA46F1" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.5.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88FEC8E4-6B53-459E-B257-BEE424463592" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.5.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A0A20D5-EAFD-4B79-818A-B834E9A11C2B" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.5.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "045AD46C-4D1E-42C9-9CFB-7924B58AE55F" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.5.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1A56E5B7-2C52-49F0-8EB1-8A090ACBF1FA" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.5.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3B412DEE-9257-4588-83F2-F8DAC3F7E1DE" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.5.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35121E51-84B8-4725-B027-AE381CA1C9F1" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDCDF3E1-280C-4539-80F8-3B131461FDF1" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CBE52F27-7AEC-40AB-9349-4C3E0E4743BF" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "01917E14-8DB6-43FE-A7B9-02C87308F09B" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D3C37FF-6B21-409F-AC19-6C2F2F429109" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3EE84614-E84C-496D-933C-5BEFD385451B" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59F6842E-041C-4076-8A2F-170DB783CC6A" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.6.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E3B53136-92CB-45D4-8CA8-589D332AEBDE" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4876E244-8F7F-4EF2-B7D9-5146BCF02F59" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8D3F7BF7-D609-44B1-9536-4A07DC149824" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CBD5E478-1654-4A75-904D-8453DDC680A0" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.7.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AF3C0E7A-533F-4AD7-BD0C-B91C0139790A" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.7.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "150B1880-BFC3-42C4-B6A3-B96C67CD671D" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DAA8F265-CE4D-46FE-9871-FDD4D6738DAB" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.8:dev:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "756A3888-E151-4FEA-8D14-F45F3192BCBA" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA3F5FAA-AD9E-4FC1-B91C-E9A561E95173" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "18A269C0-FE0F-4178-8195-955D373D9055" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.8.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCA6A474-DA24-4510-8AAA-5DF2E85B4D88" }, { "criteria": "cpe:2.3:a:ffmpeg:ffmpeg:2.8.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0D124F06-CF7E-4549-82EC-D0EC0B73D146" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*", "vulnerable": true, "matchCriteriaId": "B6B7CAD7-9D4E-4FDB-88E3-1E583210A01F" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4863BE36-D16A-4D75-90D9-FD76DB5B48B7" } ], "operator": "OR" } ] } ]