CVE-2017-9125
MEDIUMlibquicktime - Denial of Service via Heap-Based Buffer Over-Read in lqt_frame_duration
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-9125. PoCs published by qflb.wu.
AI-analyzed exploit summary The exploit demonstrates multiple denial-of-service vulnerabilities in libquicktime 1.2.4, including infinite loops, invalid memory reads, NULL pointer dereferences, and heap buffer overflows, triggered by crafted MP4 files.
Description
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file.
Exploits (1)
The exploit demonstrates multiple denial-of-service vulnerabilities in libquicktime 1.2.4, including infinite loops, invalid memory reads, NULL pointer dereferences, and heap buffer overflows, triggered by crafted MP4 files.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H