A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpeg | Dec 5, 2025 | Jan 6, 2025 |
| Debian | — | Upgrade ffmpeg | May 15, 2025 | Jan 6, 2025 |
| Ffmpeg | — | Upgrade to FFmpeg version 7.1.1Upgrade to FFmpeg version 5.1.7Upgrade to FFmpeg version 8.0Upgrade to FFmpeg version 6.1.3Upgrade to FFmpeg version 4.4.6Upgrade to FFmpeg version 7.0.3 | Aug 4, 2025 | Jan 6, 2025 |
| Ubuntu | — | Upgrade libavcodec60 (Ubuntu Pro)Upgrade libavformat60 (Ubuntu Pro)Upgrade libavcodec57 (Ubuntu Pro)Upgrade libavformat57 (Ubuntu Pro)Upgrade libavformat58 (Ubuntu Pro)Upgrade ffmpeg (Ubuntu Pro)Upgrade libavcodec58 (Ubuntu Pro) | Jun 26, 2025 | Jan 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub