CVE-2016-2399
HIGH 7.8EPSS 7.2%
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted hdlr MP4 atom.
- CVSS v3.0
- 7.8 HIGH
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 7.18% chance of exploitation in the next 30 days, 94th percentile
- Published
- 2017-01-30
- Updated
- 2024-08-05
Proof-of-concept exploits (2)
- http://www.nemux.org/2016/02/23/libquicktime-1-2-4/
- https://packetstormsecurity.com/files/135899/libquicktime-1.2.4-Integer-Overflow.html