First published: Wed Jan 11 2017(Updated: )
An integer overflow vulnerability was found in icoutils in the wrestool program. A maliciously crafted file could make the application crash or possibly allow code execution. This is a CVE for an insufficient patch for <a href="https://access.redhat.com/security/cve/CVE-2017-5208">CVE-2017-5208</a>. References: <a href="http://seclists.org/oss-sec/2017/q1/56">http://seclists.org/oss-sec/2017/q1/56</a> Upstream patch: <a href="http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=4fbe9222fd79ee31b7ec031b0be070a9a400d1d3">http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=4fbe9222fd79ee31b7ec031b0be070a9a400d1d3</a>
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icoutils Project Icoutils | <0.31.1 | |
Canonical Ubuntu Linux | =12.04 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =42.1 | |
openSUSE Leap | =42.2 | |
openSUSE openSUSE | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5331 is an integer overflow vulnerability in icoutils before version 0.31.1.
The severity of CVE-2017-5331 is high with a CVSS score of 7.8.
Icoutils Project Icoutils, Canonical Ubuntu Linux 12.04, Debian Debian Linux 8.0, Debian Debian Linux 9.0, openSUSE Leap 42.1, openSUSE Leap 42.2, and Opensuse Opensuse 13.2 are affected by CVE-2017-5331.
An attacker can exploit CVE-2017-5331 by crafting a malicious executable that triggers an integer overflow, leading to a denial of service (process crash) and potential execution of arbitrary code.
Yes, a fix for CVE-2017-5331 is available in icoutils version 0.31.1 and later.