Vulnerability Description
Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hijack of the process running with administrative privileges triggered by specially crafted input string.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cygwin | Cygwin | 1.7.2 |
Related Weaknesses (CWE)
References
- https://cygwin.com/ml/cygwin/2017-05/msg00149.htmlExploitMailing ListVendor Advisory
- https://cygwin.com/ml/cygwin/2017-05/msg00149.htmlExploitMailing ListVendor Advisory
FAQ
What is CVE-2017-7523?
CVE-2017-7523 is a vulnerability with a CVSS score of 7.5 (HIGH). Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hij...
How severe is CVE-2017-7523?
CVE-2017-7523 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7523?
Check the references section above for vendor advisories and patch information. Affected products include: Cygwin Cygwin.