8.8
CVSSv3

CVE-2017-5208

Published: 22/08/2017 Updated: 20/03/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in the wrestool program in icoutils prior to 0.31.1 allows remote malicious users to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

icoutils project icoutils

debian debian linux 8.0

redhat enterprise linux server tus 7.6

redhat enterprise linux workstation 7.0

redhat enterprise linux server aus 7.3

redhat enterprise linux server aus 7.4

redhat enterprise linux server aus 7.6

redhat enterprise linux desktop 7.0

redhat enterprise linux server eus 7.4

redhat enterprise linux server eus 7.6

redhat enterprise linux server 7.0

redhat enterprise linux server eus 7.3

redhat enterprise linux server eus 7.5

redhat enterprise linux server tus 7.3

Vendor Advisories

Synopsis Important: icoutils security update Type/Severity Security Advisory: Important Topic An update for icoutils is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base scor ...
Debian Bug report logs - #850017 icoutils: CVE-2017-5208: exploitable crash in wrestool Package: icoutils; Maintainer for icoutils is Colin Watson <cjwatson@debianorg>; Source for icoutils is src:icoutils (PTS, buildd, popcon) Reported by: Choongwoo Han <cwhantunz@gmailcom> Date: Tue, 3 Jan 2017 08:15:02 UTC Sev ...
icoutils could be made to crash or run programs as your login if it opened a specially crafted file ...
Choongwoo Han discovered that a programming error in the wrestool tool of the icoutils suite allows denial of service or the execution of arbitrary code if a malformed binary is parsed For the stable distribution (jessie), this problem has been fixed in version 0310-2+deb8u1 For the unstable distribution (sid), this problem has been fixed in ve ...
An integer overflow vulnerability was found in icoutils in the wrestool program A maliciously crafted file could make the application crash or possibly lead to arbitrary code execution This issue only affects 64-bit systems, as the result of subtracting two pointers exceeds the size of int ...