Candidate: CVE-2016-2399 PublicDate: 2017-01-30 22:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2399 http://www.nemux.org/2016/02/23/libquicktime-1-2-4/ https://packetstormsecurity.com/files/135899/libquicktime-1.2.4-Integer-Overflow.html Description: Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted hdlr MP4 atom. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Marco Romano Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_libquicktime: upstream_libquicktime: released (2:1.2.4-10) precise_libquicktime: ignored (reached end-of-life) precise/esm_libquicktime: DNE (precise was needed) trusty_libquicktime: ignored (reached end-of-life) trusty/esm_libquicktime: DNE (trusty was needed) vivid/stable-phone-overlay_libquicktime: DNE vivid/ubuntu-core_libquicktime: DNE xenial_libquicktime: released (2:1.2.4-7+deb8u1build0.16.04.1) yakkety_libquicktime: ignored (reached end-of-life) zesty_libquicktime: not-affected (2:1.2.4-10) artful_libquicktime: not-affected (2:1.2.4-10) bionic_libquicktime: not-affected (2:1.2.4-10) cosmic_libquicktime: not-affected (2:1.2.4-10) disco_libquicktime: not-affected (2:1.2.4-10) devel_libquicktime: not-affected (2:1.2.4-10)