CVE-2017-9993

Priority
Medium
Description
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and
3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename
extensions and demuxer names, which allows attackers to read arbitrary
files via crafted playlist data.
References
Package
Source: libav (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):needed
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 17.10 (Artful Aardvark):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 18.10 (Cosmic Cuttlefish):DNE
Package
Upstream:released (7:3.2.6-1)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):released (7:2.8.14-0ubuntu0.16.04.1)
Ubuntu 17.10 (Artful Aardvark):not-affected (7:3.2.6-1)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (7:3.2.6-1)
Ubuntu 18.10 (Cosmic Cuttlefish):not-affected (7:3.2.6-1)
More Information

Updated: 2018-06-26 04:15:42 UTC (commit 7799c934cca373482531a7b00e4dfe82302ceae5)