CVE-2017-6011: Buffer Overflow
An issue was discovered in icoutils 0.31.1. An out-of-bounds read leading to a buffer overflow was observed in the "simplevec" function in the "extract.c" source file. This affects icotool.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/icoutilsto a version that resolves this vulnerability.Fixed in 0.32.3-3Fixed in 0.32.3-4Fixed in 0.32.3-6
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6011?
CVE-2017-6011 is classified as a medium severity vulnerability due to the potential for buffer overflow exploitation.
How do I fix CVE-2017-6011?
To fix CVE-2017-6011, update icoutils to version 0.32.3 or later, as prior versions are vulnerable.
What software is affected by CVE-2017-6011?
CVE-2017-6011 affects icoutils version 0.31.1 and earlier on systems running Debian and Red Hat Enterprise Linux.
What type of vulnerability is CVE-2017-6011?
CVE-2017-6011 is an out-of-bounds read vulnerability that can lead to a buffer overflow.
Is CVE-2017-6011 exploitable remotely?
There is a potential for remote exploitation of CVE-2017-6011 if the vulnerable software is exposed to untrusted inputs.