PatchSiren cyber security CVE debrief
CVE-2016-2399 Libquicktime CVE debrief
CVE-2016-2399 is a libquicktime parsing flaw in which an integer overflow in quicktime_read_pascal can be triggered by a crafted hdlr MP4 atom. NVD classifies the issue as CWE-190 and lists affected libquicktime versions up to 1.2.4. The described impact includes denial of service and possibly other unspecified impact, so any system that processes untrusted MP4 content with libquicktime should treat this as a real exposure.
- Vendor
- Libquicktime
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-30
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-30
- Advisory updated
- 2026-05-13
Who should care
Security teams and developers responsible for applications, services, or pipelines that use libquicktime to open or transcode user-supplied MP4 files. Media processing systems, desktop players, and conversion workflows that accept untrusted files should review exposure.
Technical summary
NVD describes an integer overflow in quicktime_read_pascal in libquicktime 1.2.4 and earlier, reachable through a crafted hdlr MP4 atom. The vulnerability is mapped to CWE-190. NVD’s affected CPE scope ends at version 1.2.4. The record also includes advisory and exploit references, but the safe defensive takeaway is simply that malformed MP4 input can trigger unsafe integer handling in the parser.
Defensive priority
High priority wherever libquicktime is used to process untrusted media. If the library is not present or only handles fully trusted files, priority drops accordingly.
Recommended defensive actions
- Inventory systems and applications that link against or bundle libquicktime.
- Confirm whether any deployed instance is at version 1.2.4 or earlier.
- Restrict or sandbox processing of untrusted MP4 files until exposure is resolved.
- Prefer a maintained alternative or a vendor-supported fix path where available.
- Add file validation and defense-in-depth controls around media ingestion workflows.
- Monitor security advisories and package updates for libquicktime-related remediation.
Evidence notes
Source evidence is limited to the supplied NVD record and linked references. NVD describes an integer overflow in quicktime_read_pascal, affected versions through 1.2.4, and a crafted hdlr MP4 atom as the trigger. The record maps the weakness to CWE-190 and includes Debian DSA-3800 plus third-party advisory/exploit references.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-2399 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-2399
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-2399 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-2399
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://packetstormsecurity.com/files/135899/libquicktime-1.2.4-Integer-Overflow.html
[email protected] - Exploit, Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/39487/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.