PT-2017-8047 · Libquicktime+2 · Libquicktime+2

Marco Romano

+1

·

Publicado

2017-01-30

·

Atualizado

2017-11-04

·

CVE-2016-2399

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libquicktime versions 1.2.4 and earlier
Description The issue is related to an integer overflow in the quicktime read pascal function, which can be triggered by a crafted hdlr MP4 atom. This can lead to a denial of service or potentially other unspecified impacts.
Recommendations For libquicktime versions 1.2.4 and earlier, consider updating to a version later than 1.2.4 to resolve the issue. As a temporary workaround, restrict the processing of crafted hdlr MP4 atoms to minimize the risk of exploitation.

Exploit

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1688
CVE-2016-2399
DLA-844-1
DSA-3800-1
MGASA-2017-0084
OPENSUSE-SU-2024:10978-1
SUSE-SU-2017:0610-1
SUSE-SU-2017:0624-1
SUSE-SU-2017:1986-1
SUSE-SU-2017:1988-1
SUSE-SU-2017_0610-1
SUSE-SU-2017_0624-1
SUSE-SU-2017_1986-1
SUSE-SU-2017_1988-1

Produtos afetados

Alt Linux
Suse
Libquicktime