PT-2017-8047 · Libquicktime+2 · Libquicktime+2

Marco Romano

+1

·

Published

2017-01-30

·

Updated

2017-11-04

·

CVE-2016-2399

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libquicktime versions 1.2.4 and earlier
Description The issue is related to an integer overflow in the quicktime read pascal function, which can be triggered by a crafted hdlr MP4 atom. This can lead to a denial of service or potentially other unspecified impacts.
Recommendations For libquicktime versions 1.2.4 and earlier, consider updating to a version later than 1.2.4 to resolve the issue. As a temporary workaround, restrict the processing of crafted hdlr MP4 atoms to minimize the risk of exploitation.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1688
CVE-2016-2399
DLA-844-1
DSA-3800-1
MGASA-2017-0084
OPENSUSE-SU-2024:10978-1
SUSE-SU-2017:0610-1
SUSE-SU-2017:0624-1
SUSE-SU-2017:1986-1
SUSE-SU-2017:1988-1
SUSE-SU-2017_0610-1
SUSE-SU-2017_0624-1
SUSE-SU-2017_1986-1
SUSE-SU-2017_1988-1

Affected Products

Alt Linux
Suse
Libquicktime