Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Debian 8: DSA-3800-1 Critical: Libquicktime Integer Overflow DoS

debian
Calendar Grey March 2, 2017
Scroller Debian
Debian users must be aware of a critical integer overflow vulnerability in libquicktime that may lead to service denial. Immediate upgrades are urged.
Marco Romano discovered that libquicktime, a library for reading and writing QuickTime files, was vulnerable to an integer overflow attack

Summary

For the stable distribution (jessie), this problem has been fixed in
version 2:1.2.4-7+deb8u1.

For the unstable distribution (sid), this problem has been fixed in
version 2:1.2.4-10.

We recommend that you upgrade your libquicktime packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libquicktime
CVE ID: CVE-2016-2399

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.