{"id":"UBUNTU-CVE-2018-6360","details":"mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDEO elements, and accepts arbitrary URLs in a src attribute without a protocol whitelist in player/lua/ytdl_hook.lua. For example, an av://lavfi:ladspa=file= URL signifies that the product should call dlopen on a shared object file located at an arbitrary local pathname. The issue exists because the product does not consider that youtube-dl can provide a potentially unsafe URL.","modified":"2026-04-22T12:02:01.545111Z","published":"2018-01-28T02:29:00Z","upstream":["CVE-2018-6360"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-6360"},{"type":"REPORT","url":"https://github.com/mpv-player/mpv/issues/5456"},{"type":"REPORT","url":"https://github.com/mpv-player/mpv/commit/e6e6b0dcc7e9b0dbf35154a179b3dc1fcfcaff43"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2018-6360"}],"affected":[{"package":{"name":"mpv","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/mpv@0.14.0-1build1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.2-1ubuntu2","0.12.0-1","0.14.0-1","0.14.0-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.14.0-1build1","binary_name":"libmpv1"},{"binary_name":"mpv","binary_version":"0.14.0-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-6360.json"}},{"package":{"name":"mpv","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/mpv@0.27.2-1ubuntu1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.27.2-1ubuntu1"}]}],"versions":["0.26.0-3ubuntu1","0.26.0-3ubuntu2","0.27.0-2ubuntu2","0.27.0-2ubuntu3","0.27.0-2ubuntu4"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libmpv1","binary_version":"0.27.2-1ubuntu1"},{"binary_version":"0.27.2-1ubuntu1","binary_name":"mpv"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-6360.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}