PublicDateAtUSN: 2017-01-09 Candidate: CVE-2017-5208 PublicDate: 2017-08-22 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5208 http://www.openwall.com/lists/oss-security/2017/01/08/1 https://ubuntu.com/security/notices/USN-3178-1 https://ubuntu.com/security/notices/USN-4695-1 Description: Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017 Priority: medium Discovered-by: Choongwoo Han Assigned-to: leosilva CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_icoutils: upstream: http://git.savannah.gnu.org/cgit/icoutils.git/commit/?id=0d569f458f306b88f60156d60c9cf058125cf173 upstream_icoutils: released (0.31.0-4) precise_icoutils: released (0.29.1-2ubuntu0.1) precise/esm_icoutils: DNE (precise was released [0.29.1-2ubuntu0.1]) trusty_icoutils: released (0.31.0-2+deb8u2build0.14.04.1) trusty/esm_icoutils: DNE (trusty was released [0.31.0-2+deb8u2build0.14.04.1]) vivid/stable-phone-overlay_icoutils: DNE vivid/ubuntu-core_icoutils: DNE xenial_icoutils: released (0.31.0-3ubuntu0.1) yakkety_icoutils: ignored (reached end-of-life) zesty_icoutils: not-affected (0.31.1-1) artful_icoutils: not-affected (0.31.1-1) bionic_icoutils: not-affected (0.31.1-1) cosmic_icoutils: not-affected (0.31.1-1) disco_icoutils: not-affected (0.31.1-1) eoan_icoutils: not-affected (0.31.1-1) focal_icoutils: not-affected (0.31.1-1) groovy_icoutils: not-affected (0.31.1-1) devel_icoutils: not-affected (0.31.1-1)