Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.890854
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DLA-854-1)
Summary:The remote host is missing an update for the Debian 'icoutils' package(s) announced via the DLA-854-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'icoutils' package(s) announced via the DLA-854-1 advisory.

Vulnerability Insight:
Icoutils is a set of programs that deal with MS Windows icons and cursors. Resources such as icons and cursors can be extracted from MS Windows executable and library files with wrestool.

Three vulnerabilities has been found in these tools.

CVE-2017-6009

A buffer overflow was observed in wrestool.

CVE-2017-6010

A buffer overflow was observed in the extract_icons function. This issue can be triggered by processing a corrupted ico file and will result in an icotool crash.

CVE-2017-6011

An out-of-bounds read leading to a buffer overflow was observed icotool.

For Debian 7 Wheezy, these problems have been fixed in version 0.29.1-5deb7u2.

We recommend that you upgrade your icoutils packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: [link moved to references]

Affected Software/OS:
'icoutils' package(s) on Debian 7.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-6009
BugTraq ID: 96292
http://www.securityfocus.com/bid/96292
Debian Security Information: DSA-3807 (Google Search)
http://www.debian.org/security/2017/dsa-3807
https://security.gentoo.org/glsa/201801-12
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854050
RedHat Security Advisories: RHSA-2017:0837
http://rhn.redhat.com/errata/RHSA-2017-0837.html
Common Vulnerability Exposure (CVE) ID: CVE-2017-6010
BugTraq ID: 96288
http://www.securityfocus.com/bid/96288
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854054
Common Vulnerability Exposure (CVE) ID: CVE-2017-6011
BugTraq ID: 96267
http://www.securityfocus.com/bid/96267
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.