Arbitrary HTTP GET Request Vulnerability in FFmpeg’s DASH Playlist Support
CVE-2023-6605

Currently unrated

Key Information:

Vendor

FFmpeg

Status
Vendor
CVE Published:
6 January 2025

What is CVE-2023-6605?

A critical security flaw in FFmpeg's DASH playlist support has been identified, enabling attackers to execute arbitrary HTTP GET requests. This vulnerability occurs when a specially crafted DASH playlist containing malicious URLs is processed by the affected software. As a result, the machine running FFmpeg may unintentionally communicate with external servers, leading to potential data exfiltration or exposure of sensitive information.

References

Timeline

  • Vulnerability published

.