{"affected":[{"ecosystem_specific":{"binaries":[{"libquicktime0":"1.2.4-13.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP2","name":"libquicktime","purl":"pkg:rpm/suse/libquicktime&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.2.4-13.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libquicktime0":"1.2.4-13.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2","name":"libquicktime","purl":"pkg:rpm/suse/libquicktime&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.2.4-13.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libquicktime-devel":"1.2.4-13.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP2","name":"libquicktime","purl":"pkg:rpm/suse/libquicktime&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.2.4-13.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libquicktime0":"1.2.4-13.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2","name":"libquicktime","purl":"pkg:rpm/suse/libquicktime&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.2.4-13.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libquicktime0":"1.2.4-13.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"libquicktime","purl":"pkg:rpm/suse/libquicktime&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.2.4-13.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for libquicktime fixes the following issues:\n\n* CVE-2017-9122: A DoS in quicktime_read_moov function in moov.c via acrafted mp4 file was fixed. (bsc#1044077)\n* CVE-2017-9123: An invalid memory read in lqt_frame_duration via a crafted mp4 file was fixed. (bsc#1044009)\n* CVE-2017-9124: A NULL pointer dereference in quicktime_match_32 via a crafted mp4 file was fixed. (bsc#1044008)\n* CVE-2017-9125: A DoS in lqt_frame_duration function in lqt_quicktime.c via crafted mp4 file was fixed. (bsc#1044122)\n* CVE-2017-9126: A heap-based buffer overflow in quicktime_read_dref_table via a crafted mp4 file was fixed. (bsc#1044006)\n* CVE-2017-9127: A heap-based buffer overflow in quicktime_user_atoms_read_atom via a crafted mp4 file was fixed. (bsc#1044002)\n* CVE-2017-9128: A heap-based buffer over-read in quicktime_video_width via a crafted mp4 file was fixed. (bsc#1044000)\n","id":"SUSE-SU-2017:1769-1","modified":"2017-07-04T14:42:04Z","published":"2017-07-04T14:42:04Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20171769-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044000"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044002"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044006"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044008"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044009"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044077"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9123"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9124"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9125"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9126"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9127"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9128"}],"related":["CVE-2017-9122","CVE-2017-9123","CVE-2017-9124","CVE-2017-9125","CVE-2017-9126","CVE-2017-9127","CVE-2017-9128"],"summary":"Security update for libquicktime","upstream":["CVE-2017-9122","CVE-2017-9123","CVE-2017-9124","CVE-2017-9125","CVE-2017-9126","CVE-2017-9127","CVE-2017-9128"]}