FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2016-1897

This CVE name corresponds to:

Entered Topic
2016-01-17 ffmpeg -- remote attacker can access local files

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2016-1897
Phase Assigned(20160114)

Description

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.

References

Source Reference
MLIST [oss-security] 20160114 Re: Fwd: FFmpeg: stealing local files with HLS+concat
MISC http://habrahabr.ru/company/mailru/blog/274855
MISC http://security.stackexchange.com/questions/110644
SUSE openSUSE-SU-2016:0243
UBUNTU USN-2944-1