DEBIAN-CVE-2018-6360
Dashboard / Vulnerabilities / DEBIAN-CVE-2018-6360
Summary:
Details: mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDEO elements, and accepts arbitrary URLs in a src attribute without a protocol whitelist in player/lua/ytdl_hook.lua. For example, an av://lavfi:ladspa=file= URL signifies that the product should call dlopen on a shared object file located at an arbitrary local pathname. The issue exists because the product does not consider that youtube-dl can provide a potentially unsafe URL.
Affected packages
Package
Name: mpv
Purl: pkg:deb/debian/mpv?arch=source&distro=bookworm
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -0.27.0-3
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
