CVE-2023-6605
published 2025-01-06CVE-2023-6605: A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg…
PriorityP340high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
EPSS
0.27%
19.5th percentile
A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:5.1.7-0+deb12u1 (bookworm) | ffmpeg 7:5.1.7-0+deb12u1 (bookworm) |
| ffmpeg | ffmpeg | >= 0 < 7:4.3.9-0+deb11u1 | 7:4.3.9-0+deb11u1 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.7-0+deb12u1 | 7:5.1.7-0+deb12u1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.1-1 | 7:7.1.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.1-1 | 7:7.1.1-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.11-0ubuntu0.1+esm11 | 7:3.4.11-0ubuntu0.1+esm11 |
| ffmpeg | ffmpeg | >= 0 < 7:4.2.7-0ubuntu0.1+esm11 | 7:4.2.7-0ubuntu0.1+esm11 |
| ffmpeg | ffmpeg | >= 0 < 7:4.4.2-0ubuntu0.22.04.1+esm10 | 7:4.4.2-0ubuntu0.22.04.1+esm10 |
| ffmpeg | ffmpeg | >= 0 < 7:6.1.1-3ubuntu5+esm6 | 7:6.1.1-3ubuntu5+esm6 |
| ffmpeg | ffmpeg | 2.0 – 6.0 | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2025-10-21·CVSS 7.5
CVE-2023-6603 [HIGH] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: Several security issues were fixed in FFmpeg.
It was discovered that FFmpeg incorrectly handled the return values of
functions in its Firequalizer filter and in the HTTP Live Streaming (HLS)
implementation, leading to a NULL pointer dereference. If a user was
tricked into loading a crafted media file, a remote attacker could
possibly use this issue to make FFmpeg crash, resulting in a denial
of service. (CVE-2023-6603, CVE-2025-10256)
It was discovered that FFmpeg did not enforce an input format before
triggering the HTTP demuxer. A remote attacker could possibly use this
issue to perform a Server-Side Request Forgery (SSRF) attack.
(CVE-2025-6605)
It was discovered that FFmpeg incorrectly handled memory allocation in the
ALS audio decoder. If a u
Debian
CVE-2023-6605: ffmpeg - A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows ar...
vendor_debian·2023·CVSS 7.2
CVE-2023-6605 [HIGH] CVE-2023-6605: ffmpeg - A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows ar...
A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.
Scope: local
bookworm: resolved (fixed in 7:5.1.7-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.9-0+deb11u1)
forky: resolved (fixed in 7:7.1.1-1)
sid: resolved (fixed in 7:7.1.1-1)
trixie: resolved (fixed in 7:7.1.1-1)
OSV
ffmpeg vulnerabilities
osv·2025-10-21·CVSS 7.5
CVE-2023-6603 ffmpeg vulnerabilities
ffmpeg vulnerabilities
It was discovered that FFmpeg incorrectly handled the return values of
functions in its Firequalizer filter and in the HTTP Live Streaming (HLS)
implementation, leading to a NULL pointer dereference. If a user was
tricked into loading a crafted media file, a remote attacker could
possibly use this issue to make FFmpeg crash, resulting in a denial
of service. (CVE-2023-6603, CVE-2025-10256)
It was discovered that FFmpeg did not enforce an input format before
triggering the HTTP demuxer. A remote attacker could possibly use this
issue to perform a Server-Side Request Forgery (SSRF) attack.
(CVE-2025-6605)
It was discovered that FFmpeg incorrectly handled memory allocation in the
ALS audio decoder. If a user was tricked into loading a crafted media file,
a remote att
GHSA
GHSA-6r4h-f9rf-frm2: A flaw was found in FFmpeg's DASH playlist support
ghsa_unreviewed·2025-01-06
CVE-2023-6605 [HIGH] CWE-99 GHSA-6r4h-f9rf-frm2: A flaw was found in FFmpeg's DASH playlist support
A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.
OSV
CVE-2023-6605: A flaw was found in FFmpeg's DASH playlist support
osv·2025-01-06·CVSS 7.2
CVE-2023-6605 [HIGH] CVE-2023-6605: A flaw was found in FFmpeg's DASH playlist support
A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-06
Published