CVE-2017-6010
MEDIUMIcoutils - Memory Corruption
Title source: ruleDescription
An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" function in the "extract.c" source file. This issue can be triggered by processing a corrupted ico file and will result in an icotool crash.
References (5)
Scores
CVSS v3
5.5
EPSS
0.0035
EPSS Percentile
57.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-119
Status
published
Affected Products (16)
icoutils_project/icoutils
debian/debian_linux
debian/debian_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_server_aus
redhat/enterprise_linux_server_aus
redhat/enterprise_linux_server_aus
redhat/enterprise_linux_server_eus
redhat/enterprise_linux_server_eus
redhat/enterprise_linux_server_eus
redhat/enterprise_linux_server_eus
redhat/enterprise_linux_server_tus
redhat/enterprise_linux_server_tus
redhat/enterprise_linux_workstation
... and 1 more
Timeline
Published
Feb 16, 2017
Tracked Since
Feb 18, 2026