CVE-2017-9993: Debian Linux

High severity, CVSS 7.5. EPSS: 16.4% chance of exploitation in the next 30 days.

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Ffmpeg Ffmpeg: before 2.8.12 (fixed in 2.8.12); from 3.0, before 3.1.9 (fixed in 3.1.9); from 3.2, before 3.2.6 (fixed in 3.2.6); from 3.3, before 3.3.2 (fixed in 3.3.2)

Published 2017-06-28. Last modified 2026-06-17.