CVE-2017-6010: Buffer Overflow
An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extracticons" function in the "extract.c" source file. This issue can be triggered by processing a corrupted ico file and will result in an icotool crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/icoutilsto a version that resolves this vulnerability.Fixed in 0.31.2-1 - Upgrade
Upgrade
debian/icoutilsto a version that resolves this vulnerability.Fixed in 0.32.3-3Fixed in 0.32.3-4Fixed in 0.32.3-6
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6010?
CVE-2017-6010 has been classified as high severity due to its potential for causing a buffer overflow, leading to crashes of the icotool.
How do I fix CVE-2017-6010?
To fix CVE-2017-6010, upgrade icoutils to version 0.31.2-1 or any later version.
What causes CVE-2017-6010?
CVE-2017-6010 is caused by a buffer overflow in the 'extract_icons' function when processing corrupted ico files.
What software is affected by CVE-2017-6010?
CVE-2017-6010 affects icoutils version 0.31.1 and earlier, on various platforms including Debian and Red Hat Enterprise Linux.
Is there a patch available for CVE-2017-6010?
Yes, patches for CVE-2017-6010 are included in versions 0.31.2 and later of the icoutils package.