CVE-2023-6602

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Dec 31, 2024
CWE ID 99

Summary

CVE-2023-6602 is a vulnerability affecting FFmpeg's TTY Demuxer. The issue lies in the improper parsing of non-TTY-compliant input files found in HLS playlists, making it possible for attackers to exfiltrate data. This flaw could potentially be exploited to leak sensitive information, posing a risk to security. FFmpeg urges users to update their software to the latest version to mitigate this vulnerability. Successful exploitation requires an attacker to have access to the targeted HLS playlist and the ability to manipulate its content. The significance of this issue is elevated due to the potential for data exfiltration, which could result in serious consequences for affected organizations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share