CVE-2017-9122
MEDIUMlibquicktime 1.2.4 - Denial of Service via Crafted MP4 File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-9122. PoCs published by qflb.wu.
AI-analyzed exploit summary The exploit demonstrates multiple denial-of-service vulnerabilities in libquicktime 1.2.4, including infinite loops, invalid memory reads, NULL pointer dereferences, and heap buffer overflows, triggered by crafted MP4 files.
Description
The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
Exploits (1)
The exploit demonstrates multiple denial-of-service vulnerabilities in libquicktime 1.2.4, including infinite loops, invalid memory reads, NULL pointer dereferences, and heap buffer overflows, triggered by crafted MP4 files.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H