Errata ALT-PU-2020-3548-1: Information
Fixes
Published: Aug. 22, 2017
Modified: March 20, 2019
Modified: March 20, 2019
CVE-2017-5208
Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code.
Severity: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Links:
Published: Nov. 5, 2019
Modified: Nov. 5, 2019
Modified: Nov. 5, 2019
CVE-2017-5331
Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Links:
Published: Nov. 5, 2019
Modified: Nov. 6, 2019
Modified: Nov. 6, 2019
CVE-2017-5332
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Links:
- openSUSE-SU-2017:0167
- openSUSE-SU-2017:0168
- https://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=1aa9f28f7bcbdfff6a84a15ac8d9a87559b1596a
- https://bugzilla.redhat.com/show_bug.cgi?id=1412263
- [oss-security] 20170110 Re: CVE Request: icoutils: exploitable crash in wrestool programm
- DSA-3765
- 95380
- USN-3178-1
- RHSA-2017:0837
- openSUSE-SU-2017:0166
Published: Nov. 5, 2019
Modified: Nov. 7, 2019
Modified: Nov. 7, 2019
CVE-2017-5333
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
Severity: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Links:
- openSUSE-SU-2017:0167
- openSUSE-SU-2017:0168
- https://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=1a108713ac26215c7568353f6e02e727e6d4b24a
- [oss-security] 20170110 Re: CVE Request: icoutils: exploitable crash in wrestool programm
- https://bugzilla.redhat.com/show_bug.cgi?id=1412259
- DSA-3765
- USN-3178-1
- RHSA-2017:0837
- 95678
- openSUSE-SU-2017:0166