First published: Wed Jan 11 2017(Updated: )
An integer overflow vulnerability was found in extract.c while transferring resources into file memory. A maliciously crafted file could make the application crash or possibly allow code execution. References: <a href="http://seclists.org/oss-sec/2017/q1/56">http://seclists.org/oss-sec/2017/q1/56</a> Upstream patch: <a href="http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=1a108713ac26215c7568353f6e02e727e6d4b24a">http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=1a108713ac26215c7568353f6e02e727e6d4b24a</a>
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icoutils | <0.31.1 | 0.31.1 |
Icoutils Project Icoutils | <0.31.1 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server Aus | =7.3 | |
Redhat Enterprise Linux Server Aus | =7.4 | |
Redhat Enterprise Linux Server Aus | =7.6 | |
Redhat Enterprise Linux Server Aus | =7.7 | |
Redhat Enterprise Linux Server Eus | =7.3 | |
Redhat Enterprise Linux Server Eus | =7.4 | |
Redhat Enterprise Linux Server Eus | =7.5 | |
Redhat Enterprise Linux Server Eus | =7.6 | |
Redhat Enterprise Linux Server Eus | =7.7 | |
Redhat Enterprise Linux Server Tus | =7.3 | |
Redhat Enterprise Linux Server Tus | =7.6 | |
Redhat Enterprise Linux Server Tus | =7.7 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Canonical Ubuntu Linux | =12.04 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
openSUSE Leap | =42.1 | |
openSUSE Leap | =42.2 | |
openSUSE openSUSE | =13.2 |
https://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=1a108713ac26215c7568353f6e02e727e6d4b24a
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-5333 is high.
CVE-2017-5333 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
CVE-2017-5333 affects icoutils before version 0.31.1.
To fix CVE-2017-5333, update icoutils to version 0.31.1.
You can find more information about CVE-2017-5333 at the following references: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2017-01/msg00024.html), [Link 2](http://lists.opensuse.org/opensuse-security-announce/2017-01/msg00025.html), [Link 3](http://lists.opensuse.org/opensuse-security-announce/2017-01/msg00026.html).