ArchLinux: 201701-13: icoutils: arbitrary code execution
Summary
An integer overflow vulnerability was found in icoutils in the wrestool program. A maliciously crafted file could make the application crash or possibly lead to arbitrary code execution. This issue only affects 64-bit systems, as the result of subtracting two pointers exceeds the size of int.
Resolution
Upgrade to 0.31.1-1.
# pacman -Syu "icoutils>=0.31.1-1"
The problem has been fixed upstream in version 0.31.1.
References
http://www.nongnu.org/icoutils/NEWS https://seclists.org/oss-sec/2017/q1/38 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017 https://salsa.debian.org/users/sign_in https://security.archlinux.org/CVE-2017-5208
Workaround
None.