Bug 2253172 (CVE-2023-6601)
Summary: | CVE-2023-6601 ffmpeg: HLS Unsafe File Extension Bypass in FFmpeg | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Rohit Keshri <rkeshri> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | dmonzoni, osoukup, security-response-team |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2280021, 2335843, 2335844, 2335845, 2335842, 2335846, 2335847, 2335848, 2335849 | ||
Bug Blocks: |
Description
Rohit Keshri
2023-12-06 11:24:50 UTC
CVE-2023-6601: HLS Unsafe File Extension Bypass CVE-2023-6602: HLS Force TTY Demuxer CVE-2023-6603: HLS EXT-X-MAP Null Dereference CVE-2023-6604: HLS XBIN Demuxer DoS Amplification CVE-2023-6605: DASH Playlist SSRF Created chromium tracking bugs for this issue: Affects: epel-all [bug 2266129] Created ffmpeg tracking bugs for this issue: Affects: epel-all [bug 2266128] Affects: fedora-all [bug 2266131] Created qt5-qtwebengine tracking bugs for this issue: Affects: epel-all [bug 2266130] Affects: fedora-all [bug 2266132] Created qt6-qtwebengine tracking bugs for this issue: Affects: fedora-all [bug 2266133] Please open separate bugs for each CVE along with upstream report references. Putting multiple issues in one bug makes it quite difficult to manage them. FWIW, The FFmpeg in Fedora 39+ is not affected by any of these. Ok, actually, FFmpeg is still affected by CVE-2023-6605: DASH Playlist SSRF I just noticed I misread the log. Where's the upstream report? Ok will make them separate. |