Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-6009

Опубликовано: 16 фев. 2017
Источник: debian
EPSS Низкий

Описание

An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "len" parameter for memcpy is not checked for size and thus becomes a negative integer in the process, resulting in a failed memcpy. This affects wrestool.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
icoutilsfixed0.31.2-1package

Примечания

  • Fixed by: http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=f148ae5af1c9eeb85610a5653a7f625dd6c3ac2e

  • Proposed patch from Red Hat contributor: https://bugzilla.redhat.com/attachment.cgi?id=1256407

EPSS

Процентиль: 51%
0.0028
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "len" parameter for memcpy is not checked for size and thus becomes a negative integer in the process, resulting in a failed memcpy. This affects wrestool.

CVSS3: 8.1
redhat
почти 9 лет назад

An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "len" parameter for memcpy is not checked for size and thus becomes a negative integer in the process, resulting in a failed memcpy. This affects wrestool.

CVSS3: 5.5
nvd
больше 8 лет назад

An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "len" parameter for memcpy is not checked for size and thus becomes a negative integer in the process, resulting in a failed memcpy. This affects wrestool.

CVSS3: 5.5
github
больше 3 лет назад

An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "len" parameter for memcpy is not checked for size and thus becomes a negative integer in the process, resulting in a failed memcpy. This affects wrestool.

suse-cvrf
больше 8 лет назад

Security update for icoutils

EPSS

Процентиль: 51%
0.0028
Низкий