Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian 7: DLA-2042-2 Critical: libquicktime Denial Of Service

debian lts
Calendar Grey July 28, 2017
Dist Debian Esm H88
Concerns have been raised regarding several vulnerabilities within libquicktime that impact Debian 7. An upgrade is advised to alleviate potential threats.
CVE-2017-9122 The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU

Summary

The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows
remote attackers to cause a denial of service (infinite loop and CPU
consumption) via a crafted mp4 file.

CVE-2017-9123

The lqt_frame_duration function in lqt_quicktime.c in libquicktime
1.2.4 allows remote attackers to cause a denial of service (invalid
memory read and application crash) via a crafted mp4 file.

CVE-2017-9124

The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows
remote attackers to cause a denial of service (NULL pointer dereference
and application crash) via a crafted mp4 file.

CVE-2017-9125

The lqt_frame_duration function in lqt_quicktime.c in libquicktime
1.2.4 allows remote attackers to cause a denial of service (heap-based
buffer over-read) via a crafted mp4 file.

CVE-2017-9126

The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4
allows remote attackers to cause a denial of service (heap-based buffer

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: libquicktime
Version: 2:1.2.4-3+deb7u2
CVE ID: CVE-2017-9122 CVE-2017-9123 CVE-2017-9124 CVE-2017-9125
Debian Bug: 864664

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here