Bug 1051855 (CVE-2017-12145) - VUL-1: CVE-2017-12145: libquicktime: Allocation failure in functionquicktime_read_ftyp in ftyp.c, which allows attackers to cause DoS
Summary: VUL-1: CVE-2017-12145: libquicktime: Allocation failure in functionquicktime_...
Status: RESOLVED WORKSFORME
Alias: CVE-2017-12145
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/189460/
Whiteboard: CVSSv2:SUSE:CVE-2017-12145:5.0:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2017-08-02 11:47 UTC by Johannes Segitz
Modified: 2020-06-29 06:29 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
Reproducer (1.35 KB, video/mp4)
2017-08-02 11:47 UTC, Johannes Segitz
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2017-08-02 11:47:17 UTC
Created attachment 734932 [details]
Reproducer

CVE-2017-12145

In libquicktime 1.2.4, an allocation failure was found in the function
quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial
of service via a crafted file.

qtinfo allocation-failed-in_quicktime_read_ftyp

qtinfo lives in libquicktime-tools from OBS

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-12145
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12145
Comment 1 Kristyna Streitova 2017-08-04 16:22:00 UTC
I tested the latest libquicktime in SLE12SP2, openSUSE:Factory and openSUSE:Leap and it seems that we are not affected thanks to our recent security fix for multiple CVEs (patch libquicktime-<version>-multiple_vulnerabilities.patch for CVEs from CVE-2017-9122 to CVE-2017-9128). 

I haven't tested SLE11 but as we have the same multiple_vulnerabilities patch there I expect the same results. 

Test output for SLE12SP2:
-------------------------
# zypper se -s libquicktime | grep ^i
i+ | libquicktime-tools  | package | 1.2.4-0      | x86_64 | (System Packages) 
i  | libquicktime0       | package | 1.2.4-14.3.1 | x86_64 | SLES12-SP2-Updates

# qtinfo allocation-failed-in_quicktime_read_ftyp 
[core] Error: Opening failed (unsupported filetype)
Couldn't open allocation-failed-in_quicktime_read_ftyp

---

I'm reassigning it back to the security-team.
Comment 2 Marcus Meissner 2017-10-26 08:41:05 UTC
already fixed by oither cve fixes.