CVE-2023-6601Resource Injection in Ffmpeg

Severity
4.7MEDIUMNVD
EPSS
0.0%
top 88.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 6

Description

A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

debiandebian/ffmpeg< ffmpeg 7:6.1-1 (forky)
Debianffmpeg/ffmpeg< 7:6.1-1+1
NVDffmpeg/ffmpeg2.06.0

🔴Vulnerability Details

2
OSV
CVE-2023-6601: A flaw was found in FFmpeg's HLS demuxer2025-01-06
GHSA
GHSA-wj7r-cv36-mxr3: A flaw was found in FFmpeg's HLS demuxer2025-01-06

📋Vendor Advisories

1
Debian
CVE-2023-6601: ffmpeg - A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing un...2023