vendor:
libquicktime
by:
Marco Romano
7.8
CVSS
HIGH
Integer Overflow
Integer Overflow
CWE
Product Name: libquicktime
Affected Version From: <= 1.2.4
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2016-2399
CPE:
Platforms Tested:
2016
libquicktime 1.2.4 Integer Overflow
There needs to be an mp4 file with these nested atoms to trigger the bug: moov -> trak -> mdia -> hdlr
Mitigation:
Upgrade to a version of libquicktime higher than 1.2.4