CVE-2023-6603
published 2024-12-31CVE-2023-6603: A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null…
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.56%
43.0th percentile
A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:5.0.1-2 (bookworm) | ffmpeg 7:5.0.1-2 (bookworm) |
| ffmpeg | ffmpeg | >= 0 < 7:4.3.9-0+deb11u2 | 7:4.3.9-0+deb11u2 |
| ffmpeg | ffmpeg | >= 0 < 7:5.0.1-2 | 7:5.0.1-2 |
| ffmpeg | ffmpeg | >= 0 < 7:5.0.1-2 | 7:5.0.1-2 |
| ffmpeg | ffmpeg | >= 0 < 7:5.0.1-2 | 7:5.0.1-2 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.11-0ubuntu0.1+esm11 | 7:3.4.11-0ubuntu0.1+esm11 |
| ffmpeg | ffmpeg | >= 0 < 7:4.2.7-0ubuntu0.1+esm11 | 7:4.2.7-0ubuntu0.1+esm11 |
| ffmpeg | ffmpeg | >= 0 < 7:4.4.2-0ubuntu0.22.04.1+esm10 | 7:4.4.2-0ubuntu0.22.04.1+esm10 |
| ffmpeg | ffmpeg | >= 0 < 7:6.1.1-3ubuntu5+esm6 | 7:6.1.1-3ubuntu5+esm6 |
| ffmpeg | ffmpeg | 2.0 – 6.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ffmpeg vulnerabilities
osv·2025-10-21·CVSS 7.5
CVE-2023-6603 [HIGH] ffmpeg vulnerabilities
ffmpeg vulnerabilities
It was discovered that FFmpeg incorrectly handled the return values of
functions in its Firequalizer filter and in the HTTP Live Streaming (HLS)
implementation, leading to a NULL pointer dereference. If a user was
tricked into loading a crafted media file, a remote attacker could
possibly use this issue to make FFmpeg crash, resulting in a denial
of service. (CVE-2023-6603, CVE-2025-10256)
It was discovered that FFmpeg did not enforce an input format before
triggering the HTTP demuxer. A remote attacker could possibly use this
issue to perform a Server-Side Request Forgery (SSRF) attack.
(CVE-2025-6605)
It was discovered that FFmpeg incorrectly handled memory allocation in the
ALS audio decoder. If a user was tricked into loading a crafted media file,
a remote att
GHSA
GHSA-gxvx-w63c-jprw: A flaw was found in FFmpeg's HLS playlist parsing
ghsa_unreviewed·2024-12-31
CVE-2023-6603 [HIGH] CWE-476 GHSA-gxvx-w63c-jprw: A flaw was found in FFmpeg's HLS playlist parsing
A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.
OSV
CVE-2023-6603: A flaw was found in FFmpeg's HLS playlist parsing
osv·2024-12-31·CVSS 7.5
CVE-2023-6603 [HIGH] CVE-2023-6603: A flaw was found in FFmpeg's HLS playlist parsing
A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.
Ubuntu
FFmpeg vulnerability
vendor_ubuntu·2025-11-26
CVE-2023-6603 FFmpeg vulnerability
Title: FFmpeg vulnerability
Summary: FFmpeg could be made to crash if it opened a specially crafted file.
It was discovered that FFmpeg did not properly handle the parsing of
certain malformed HLS playlists. If a user were tricked into opening a
specially crafted HLS playlist, an attacker could possibly use this issue
to cause FFmpeg to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2025-10-21·CVSS 7.5
CVE-2023-6603 [HIGH] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: Several security issues were fixed in FFmpeg.
It was discovered that FFmpeg incorrectly handled the return values of
functions in its Firequalizer filter and in the HTTP Live Streaming (HLS)
implementation, leading to a NULL pointer dereference. If a user was
tricked into loading a crafted media file, a remote attacker could
possibly use this issue to make FFmpeg crash, resulting in a denial
of service. (CVE-2023-6603, CVE-2025-10256)
It was discovered that FFmpeg did not enforce an input format before
triggering the HTTP demuxer. A remote attacker could possibly use this
issue to perform a Server-Side Request Forgery (SSRF) attack.
(CVE-2025-6605)
It was discovered that FFmpeg incorrectly handled memory allocation in the
ALS audio decoder. If a u
Debian
CVE-2023-6603: ffmpeg - A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a d...
vendor_debian·2023·CVSS 7.5
CVE-2023-6603 [HIGH] CVE-2023-6603: ffmpeg - A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a d...
A flaw was found in FFmpeg's HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.
Scope: local
bookworm: resolved (fixed in 7:5.0.1-2)
bullseye: resolved (fixed in 7:4.3.9-0+deb11u2)
forky: resolved (fixed in 7:5.0.1-2)
sid: resolved (fixed in 7:5.0.1-2)
trixie: resolved (fixed in 7:5.0.1-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-31
Published