PT-2017-16437 · Icoutils+5 · Icoutils+5

Published

2017-01-11

·

Updated

2024-08-19

·

CVE-2017-5332

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions icoutils versions prior to 0.31.1
Description The issue allows local users to cause a denial of service and execute arbitrary code via a crafted executable. This is due to the extract group icon cursor resource function in wrestool/extract.c accessing unallocated memory.
Recommendations For versions prior to 0.31.1, update to version 0.31.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the extract group icon cursor resource function in wrestool/extract.c to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3528
ALT-PU-2020-3548
ALT-PU-2024-11162
CESA-2017_0837
CVE-2017-5332
DLA-789-1
DSA-3765-1
MGASA-2017-0044
OPENSUSE-SU-2017_0166-1
OPENSUSE-SU-2017_0167-1
OPENSUSE-SU-2017_0168-1
RHSA-2017:0837
RHSA-2017_0837
USN-3178-1
USN-4695-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Icoutils