FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of a local file.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.1.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.9"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.10"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.11"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.12"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.13"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.14"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.15"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.16"
},
{
"introduced": "0"
},
{
"last_affected": "2.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.3.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.9"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.10"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.11"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.12"
},
{
"introduced": "0"
},
{
"last_affected": "2.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.5.9"
},
{
"introduced": "0"
},
{
"last_affected": "2.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.8-dev"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.8.4"
}
]
}