CVE-2017-5332
Published: 11 January 2017
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
Priority
CVSS 3 base score: 7.8
Status
Package | Release | Status |
---|---|---|
icoutils Launchpad, Ubuntu, Debian |
Upstream |
Released
(0.31.1-1)
|
Ubuntu 21.04 (Hirsute Hippo) |
Not vulnerable
(0.31.1-1)
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(0.31.1-1)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(0.31.1-1)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(0.31.1-1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Released
(0.31.0-3ubuntu0.1)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was released [0.31.0-2+deb8u2build0.14.04.1])
|
|
Patches: Upstream: http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=1aa9f28f7bcbdfff6a84a15ac8d9a87559b1596a |
Notes
Author | Note |
---|---|
mdeslaur | This CVE is for "all of 1aa9f28f7bcbdfff6a84a15ac8d9a87559b1596a and also the index correction in 1a108713ac26215c7568353f6e02e727e6d4b24a." |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5332
- http://www.openwall.com/lists/oss-security/2017/01/10/4
- https://usn.ubuntu.com/usn/usn-3178-1
- https://usn.ubuntu.com/usn/usn-4695-1
- NVD
- Launchpad
- Debian