CVE-2016-1897

MEDIUM5.5EPSS 52.1%

libav - security update

發布日:2016/1/15修改日:2026/4/28
也稱為:DEBIAN-CVE-2016-1897

描述

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.5CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

參考連結(1)