Bug 961937 (CVE-2016-1897) - VUL-0: CVE-2016-1897, CVE-2016-1898: FFmpeg, libav: Local file disclosure via HLS
Summary: VUL-0: CVE-2016-1897, CVE-2016-1898: FFmpeg, libav: Local file disclosure via...
Status: RESOLVED FIXED
Alias: CVE-2016-1897
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.1
: P3 - Medium : Major
Target Milestone: ---
Assignee: Jan Engelhardt
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/160685/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-01-14 16:44 UTC by Johannes Segitz
Modified: 2018-07-18 14:43 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2016-01-14 16:44:19 UTC
CVE-2016-1897

http://seclists.org/oss-sec/2016/q1/91
"As far as we can tell, there are two distinct cross-origin issues
within FFmpeg's URL processing. Use CVE-2016-1897 for the concat issue
(which is fully described in the blog/274855 reference) and
CVE-2016-1898 for the subfile issue (which is mentioned but not
described in the blog/274855 reference).

The essential problem is that a crafted file forces the victim to
visit an arbitrary external URL, but this URL is constructed using
data from the victim's local filesystem."

English translation of the original report:
https://translate.google.com/translate?sl=ru&tl=en&u=http%3A%2F%2Fhabrahabr.ru%2Fcompany%2Fmailru%2Fblog%2F274855%2F

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1897
http://seclists.org/oss-sec/2016/q1/91
Comment 1 Swamp Workflow Management 2016-01-14 23:00:23 UTC
bugbot adjusting priority
Comment 2 Bernhard Wiedemann 2016-01-18 11:00:29 UTC
This is an autogenerated message for OBS integration:
This bug (961937) was mentioned in
https://build.opensuse.org/request/show/354498 42.1 / ffmpeg
Comment 3 Johannes Segitz 2016-01-21 13:48:56 UTC
Will you also provide submits for 13.2?
Comment 4 Andreas Stieger 2016-01-21 14:02:44 UTC
(In reply to Johannes Segitz from comment #3)
> Will you also provide submits for 13.2?

openSUSE:13.2:Update/libavutil
Comment 5 Swamp Workflow Management 2016-01-25 21:11:23 UTC
openSUSE-SU-2016:0243-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 961937
CVE References: CVE-2016-1897,CVE-2016-1898
Sources used:
openSUSE Leap 42.1 (src):    ffmpeg-2.8.5-12.1
Comment 6 Jan Engelhardt 2016-04-24 19:05:30 UTC
openSUSE-SU-2016:0243-1: An update that fixes two vulnerabilities was made available.
Comment 7 Swamp Workflow Management 2018-07-18 14:43:45 UTC
This is an autogenerated message for OBS integration:
This bug (961937) was mentioned in
https://build.opensuse.org/request/show/623663 15.0+42.3+Backports:SLE-12-SP2 / chromium+codec2+ffmpeg-2+ffmpeg-3+ffmpeg-4+libsodium+libvpx-1_6+zeromq