← Vulnerability feed

Vulnerability record · CVE-2017-12143 · published 2 August 2017

CVE-2017-12143: Libquicktime improper input validation vulnerability

LLibquicktime · Libquicktime

In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted file.

6.5 CVSS 3.0 Medium EPSS 1.0% · top 37.5% CWE-20 · Improper input validation
6.5CVSS 3.0 base score, v2 4.3
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted file.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12143 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2016-2399Libquicktime integer overflow vulnerabilityInteger overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or poss…EPSS 7.2%6.5CVE-2017-12145Libquicktime improper input validation vulnerabilityIn libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of ser…EPSS 1.1%6.5CVE-2017-9122Libquicktime vulnerabilityThe quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumpt…EPSS 6.5%6.5CVE-2017-9123Libquicktime out-of-bounds read vulnerabilityThe lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read an…EPSS 3.8%6.5CVE-2017-9124Libquicktime null pointer dereference vulnerabilityThe quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and ap…EPSS 3.8%6.5CVE-2017-9125Libquicktime out-of-bounds read vulnerabilityThe lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over…EPSS 4.9%6.5CVE-2017-9126Libquicktime memory buffer overflow vulnerabilityThe quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overfl…EPSS 4.0%6.5CVE-2017-9127Libquicktime memory buffer overflow vulnerabilityThe quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buf…EPSS 5.1%

Source: NIST National Vulnerability Database (record CVE-2017-12143), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.