CVE-2016-1897
MEDIUM5.5EPSS 52.1%libav - security update
發布日:2016/1/15修改日:2026/4/28
也稱為:DEBIAN-CVE-2016-1897
描述
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.
受影響套件(2)
- Debian/ffmpegfrom 0, < 7:2.8.5-1
- Debian/libavfrom 0, < 6:0.8.17-2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |