Описание
Security update for libquicktime
This update for libquicktime fixes the following issues:
- A crafted MP4 file could have caused libquicktime to crash or lead to undefined behaviour (bsc#1022805, CVE-2016-2399)
Список пакетов
SUSE Linux Enterprise Software Development Kit 11 SP4
libquicktime-1.0.3-5.2
libquicktime-devel-1.0.3-5.2
Ссылки
- Link for SUSE-SU-2017:0624-1
- E-Mail link for SUSE-SU-2017:0624-1
- SUSE Security Ratings
- SUSE Bug 1022805
- SUSE CVE CVE-2016-2399 page
Описание
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted hdlr MP4 atom.
Затронутые продукты
SUSE Linux Enterprise Software Development Kit 11 SP4:libquicktime-1.0.3-5.2
SUSE Linux Enterprise Software Development Kit 11 SP4:libquicktime-devel-1.0.3-5.2
Ссылки
- CVE-2016-2399
- SUSE Bug 1022805