Severity
8.8HIGH
EPSS
1.6%
top 18.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 22
Latest updateMay 14

Description

Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

Debianicoutils< 0.31.0-4+3
Ubuntuicoutils< 0.31.0-3ubuntu0.1

Also affects: Debian Linux 8.0, Enterprise Linux 7.3, 7.4, 7.6, 7.5

🔴Vulnerability Details

4
GHSA
GHSA-3v6p-5m88-xqx6: Integer overflow in the wrestool program in icoutils before 02022-05-14
OSV
icoutils vulnerabilities2021-01-18
OSV
CVE-2017-5208: Integer overflow in the wrestool program in icoutils before 02017-08-22
CVEList
CVE-2017-5208: Integer overflow in the wrestool program in icoutils before 02017-08-22

📋Vendor Advisories

5
Ubuntu
icoutils vulnerabilities2021-01-18
Ubuntu
icoutils vulnerabilities2017-01-24
Red Hat
icoutils: Check_offset overflow on 64-bit systems2017-01-08
Red Hat
icoutils: Check_offset overflow on 64-bit systems2017-01-08
Debian
CVE-2017-5208: icoutils - Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote...2017

💬Community

5
Bugzilla
CVE-2017-14955 check-mk: Mishandles certain errors within the failed-login save feature because of a race condition2017-10-03
Bugzilla
CVE-2017-5331 icoutils: Check_offset overflow on 64-bit systems2017-01-11
Bugzilla
CVE-2017-5208 icoutils: Check_offset overflow on 64-bit systems [fedora-all]2017-01-09
Bugzilla
CVE-2017-5208 icoutils: Check_offset overflow on 64-bit systems [epel-6]2017-01-09
Bugzilla
CVE-2017-5208 icoutils: Check_offset overflow on 64-bit systems2017-01-09
CVE-2017-5208 (HIGH CVSS 8.8) | Integer overflow in the wrestool pr | cvebase.io