suse · CVE-2017-9127

Quick triage

Priority: medium Published: 2021-05-30 13:56:45 UTC Updated: 2026-04-17 16:09:10 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-9127 severity moderate: SUSE including 22 source package names (libquicktime-1.0.3-6.5.1, libquicktime-1.2.4+git20180804.fff99cd-1.19, …), 50 product×package rows across 27 product lines (SUSE Linux Enterprise Desktop 12 SP2, SUSE Linux Enterprise Desktop 12 SP4, … (27 product lines)): Fixed 50.

Description:

The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.

cvelogic Threat Intelligence