ZeroHour

CVE-2017-5332

CVSS 3.1
7.8 high
EPSS
2%p81
Published
()
Modified
Description

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

Vendors
icoutils projectredhatcanonicaldebianopensuse
Products
icoutils, enterprise linux, enterprise linux desktop, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, ubuntu linux, debian linux, leap, opensuse
Weakness
CWE-119
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.