« List of all CVEs

CVE-2016-1898

Published: 1/15/2016 Last updated: 8/5/2024 Reserved: 1/14/2016

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (3)

conf-ffmpeg ffmpeg opus

Products affected (1)

Product Vendor Version
n/a n/a 10 Version 1809 for 32-bit Systems

References (22)