HIGH
icoutils: Buffer overflow in the simple_vec function
Published Feb 16, 2017
8.1
HIGHCVSS 3.0
EPSS 1.54%
Description
An issue was discovered in icoutils 0.31.1. An out-of-bounds read leading to a buffer overflow was observed in the "simple_vec" function in the "extract.c" source file. This affects icotool.
Affected products
No data.
Configuration 1
- 0.31.1
Configuration 2
OR
- 8.0
- 9.0
Configuration 3
OR
- 7.0
- 7.0
- 7.3
- 7.4
- 7.6
- 7.3
- 7.4
- 7.5
- 7.6
- 7.3
- 7.6
- 7.0
No data.
Red Hat Enterprise Linux 7
icoutils-0:0.31.3-1.el7_3
Fixed · RHSA-2017:0837
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | icoutils-0:0.31.3-1.el7_3 | Fixed | RHSA-2017:0837 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (10)
- http://rhn.redhat.com/errata/RHSA-2017-0837.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.debian.org/security/2017/dsa-3807 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.securityfocus.com/bid/96267 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-6011 Vendor Advisory
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854054 x_refsource_MISCExploitIssue TrackingMailing ListVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1422908 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-15079 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-6011
- https://security.gentoo.org/glsa/201801-12 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-6011
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2017-0837.html | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| http://www.debian.org/security/2017/dsa-3807 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.securityfocus.com/bid/96267 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-6011 | Vendor Advisory | |
| https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854054 | x_refsource_MISCExploitIssue TrackingMailing ListVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1422908 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-15079 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-6011 | ||
| https://security.gentoo.org/glsa/201801-12 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2017-6011 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 16, 2017
Updated Aug 5, 2024
Reserved Feb 16, 2017
Link CVE-2017-6011
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2017-15079 Assigner mitre
Published Feb 16, 2017
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2017-15079