DSA-3800Vendor advisory
http://www.debian.org/security/2017/dsa-3800 CVE-2016-2399
HIGH
libquicktime 1.2.4 - Integer Overflow
Record summary
CVE-2016-2399 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted hdlr MP4 atom.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBlibquicktime 1.2.4 - Integer OverflowExploitDB exploitby Marco RomanoNot analyzed1 file
References
6nemux.org
http://www.nemux.org/2016/02/23/libquicktime-1-2-4 95880vdb entry
http://www.securityfocus.com/bid/95880 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-2399 packetstormsecurity.com
https://packetstormsecurity.com/files/135899/libquicktime-1.2.4-Integer-Overflow.html 39487exploit
https://www.exploit-db.com/exploits/39487