Bug 1051859 (CVE-2017-12143) - VUL-1: CVE-2017-12143: libquicktime: Allocation failure in functionquicktime_read_info in lqt_quicktime.c, which allows attackers to cause DoS
Summary: VUL-1: CVE-2017-12143: libquicktime: Allocation failure in functionquicktime_...
Status: RESOLVED WORKSFORME
Alias: CVE-2017-12143
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/189458/
Whiteboard: CVSSv2:SUSE:CVE-2017-12143:5.0:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2017-08-02 11:52 UTC by Johannes Segitz
Modified: 2020-06-29 06:29 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
Reproducer (1.24 KB, video/mp4)
2017-08-02 11:52 UTC, Johannes Segitz
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2017-08-02 11:52:39 UTC
Created attachment 734935 [details]
Reproducer

CVE-2017-12143

In libquicktime 1.2.4, an allocation failure was found in the function
quicktime_read_info in lqt_quicktime.c, which allows attackers to cause
a denial of service via a crafted file.

qtinfo allocation-failed-in_quicktime_read_info

qtinfo lives in libquicktime-tools from OBS

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-12143
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12143
Comment 1 Kristyna Streitova 2017-08-04 16:21:21 UTC
I tested the latest libquicktime in SLE12SP2, openSUSE:Factory and openSUSE:Leap and it seems that we are not affected thanks to our recent security fix for multiple CVEs (patch libquicktime-<version>-multiple_vulnerabilities.patch for CVEs from CVE-2017-9122 to CVE-2017-9128). 

I haven't tested SLE11 but as we have the same multiple_vulnerabilities patch there I expect the same results. 

Test output for SLE12SP2:
-------------------------
# zypper se -s libquicktime | grep ^i
i+ | libquicktime-tools | package  | 1.2.4-0      | x86_64 | (System Packages) 
i  | libquicktime0      | package  | 1.2.4-14.3.1 | x86_64 | SLES12-SP2-Updates

# qtinfo allocation-failed-in_quicktime_read_info 
[core] Error: Opening failed (unsupported filetype)
Couldn't open allocation-failed-in_quicktime_read_info

---

I'm reassigning it back to the security-team.
Comment 2 Marcus Meissner 2017-10-26 08:42:48 UTC
already fixed by other cve fixes.