Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5332

Опубликовано: 04 нояб. 2019
Источник: debian
EPSS Низкий

Описание

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
icoutilsfixed0.31.1-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1249276

  • Fixed by: http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=1aa9f28f7bcbdfff6a84a15ac8d9a87559b1596a

  • Fixed by: http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=1a108713ac26215c7568353f6e02e727e6d4b24a

  • https://www.openwall.com/lists/oss-security/2017/01/10/4

  • CVE for "all of 1aa9f28f7bcbdfff6a84a15ac8d9a87559b1596a and also the index correction in

  • 1a108713ac26215c7568353f6e02e727e6d4b24a."

EPSS

Процентиль: 46%
0.00234
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

CVSS3: 2.8
redhat
почти 9 лет назад

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

CVSS3: 7.8
nvd
около 6 лет назад

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

CVSS3: 7.8
github
больше 3 лет назад

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

suse-cvrf
почти 9 лет назад

Security update for icoutils

EPSS

Процентиль: 46%
0.00234
Низкий