{"affected":[{"ecosystem_specific":{"binaries":[{"libquicktime":"1.0.3-6.5.1","libquicktime-devel":"1.0.3-6.5.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 11 SP4","name":"libquicktime","purl":"pkg:rpm/suse/libquicktime&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.0.3-6.5.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for libquicktime fixes the following issues:\n\nSecurity issues fixed:\n- CVE-2017-9122: A DoS in quicktime_read_moov function in moov.c via a crafted mp4 file was fixed. (bsc#1044077)\n- CVE-2017-9123: An invalid memory read in lqt_frame_duration via a crafted mp4 file was fixed. (bsc#1044009)\n- CVE-2017-9124: A NULL pointer dereference in quicktime_match_32 via a crafted mp4 file was fixed. (bsc#1044008)\n- CVE-2017-9125: A DoS in lqt_frame_duration function in lqt_quicktime.c via crafted mp4 file was fixed. (bsc#1044122)\n- CVE-2017-9126: A heap-based buffer overflow in quicktime_read_dref_table via a crafted mp4 file was fixed. (bsc#1044006)\n- CVE-2017-9127: A heap-based buffer overflow in quicktime_user_atoms_read_atom via a crafted mp4 file was fixed. (bsc#1044002)\n- CVE-2017-9128: A heap-based buffer over-read in quicktime_video_width via a crafted mp4 file was fixed. (bsc#1044000)\n- CVE-2016-2399: Adjust fix to prevent endless loop when there are less than 256 bytes to read. (bsc#1022805)\n\n","id":"SUSE-SU-2017:1988-1","modified":"2017-07-28T08:41:51Z","published":"2017-07-28T08:41:51Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20171988-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1022805"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044000"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044002"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044006"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044008"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044009"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044077"},{"type":"REPORT","url":"https://bugzilla.suse.com/1044122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-2399"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9123"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9124"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9125"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9126"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9127"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9128"}],"related":["CVE-2016-2399","CVE-2017-9122","CVE-2017-9123","CVE-2017-9124","CVE-2017-9125","CVE-2017-9126","CVE-2017-9127","CVE-2017-9128"],"summary":"Security update for libquicktime","upstream":["CVE-2016-2399","CVE-2017-9122","CVE-2017-9123","CVE-2017-9124","CVE-2017-9125","CVE-2017-9126","CVE-2017-9127","CVE-2017-9128"]}