Updated icoutils packages fix security vulnerability
Publication date: 07 Feb 2017Modification date: 07 Feb 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2017-5208 , CVE-2017-5331 , CVE-2017-5332 , CVE-2017-5333
Description
Multiple programming errors in the wrestool tool of the icoutils suite allows denial of service or the execution of arbitrary code if a malformed binary is parsed (CVE-2017-5208, CVE-2017-5331, CVE-2017-5332, CVE-2017-5333).
References
- https://bugs.mageia.org/show_bug.cgi?id=20091
- http://openwall.com/lists/oss-security/2017/01/08/5
- http://openwall.com/lists/oss-security/2017/01/11/3
- https://www.debian.org/security/2017/dsa-3756
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5208
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5331
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5332
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5333
SRPMS
5/core
- icoutils-0.31.1-1.mga5