PT-2024-15022 · FFmpeg+1 · Ffmpeg+1

Harvey Phillips

·

Published

2023-12-01

·

Updated

2026-01-22

·

CVE-2023-6601

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions FFmpeg (affected versions not specified)
Description A flaw was found in FFmpeg's HLS demuxer, allowing bypassing of unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-02727
CVE-2023-6601
DLA-4241-1
DSA-5985-1
OPENSUSE-SU-2026:10027-1
OPENSUSE-SU-2026:10028-1
OPENSUSE-SU-2026:20710-1
SUSE-SU-2026:0198-1
SUSE-SU-2026:0229-1

Affected Products

Debian
Ffmpeg