Back

HIGH

icoutils: Buffer overflow in the decode_ne_resource_id function

Published Feb 16, 2017

Description

An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "len" parameter for memcpy is not checked for size and thus becomes a negative integer in the process, resulting in a failed memcpy. This affects wrestool.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 16, 2017
Updated Aug 5, 2024
Reserved Feb 16, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 3, 2017