PatchSiren cyber security CVE debrief
CVE-2017-6009 Redhat CVE debrief
CVE-2017-6009 is a buffer overflow in icoutils 0.31.1, specifically in the decode_ne_resource_id function used by wrestool. The flaw is triggered by an unchecked memcpy length that can become negative, creating a denial-of-service risk and possible memory corruption. Because the CVSS vector requires local access and user interaction, this is most relevant on systems where untrusted inputs are processed with wrestool.
- Vendor
- Redhat
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-16
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-16
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams responsible for systems that install or use icoutils/wrestool, especially Linux distributions and environments that may process untrusted Windows resource files locally. Downstream package maintainers should also pay attention because the NVD record lists affected Debian and Red Hat Enterprise Linux-related CPEs.
Technical summary
NVD classifies the weakness as CWE-119 and scores it CVSS 3.0 5.5 (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). The vulnerable path is decode_ne_resource_id in restable.c, where the memcpy length parameter is not validated before use. According to the record, the problem affects icoutils 0.31.1 and wrestool, and downstream advisories were issued by Red Hat, Debian, and Gentoo.
Defensive priority
Medium
Recommended defensive actions
- Apply the vendor or distribution updates that address CVE-2017-6009 for icoutils/wrestool.
- Inventory hosts for icoutils 0.31.1 and related downstream packages to identify exposure.
- Limit who can run wrestool on untrusted inputs, since the CVSS vector requires local access and user interaction.
- Review workflows that process Windows resource files and treat external inputs as untrusted.
- Use downstream security advisories to confirm your platform-specific remediation path.
Evidence notes
Primary evidence comes from the NVD CVE record and its linked advisories. The record identifies icoutils 0.31.1 as vulnerable, names decode_ne_resource_id in restable.c, and assigns CWE-119 with CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H. Linked references include Red Hat RHSA-2017-0837, Debian DSA-3807, Gentoo GLSA 201801-12, SecurityFocus BID 96292, and the Debian bug tracker entry 854050.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6009 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6009
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6009 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6009
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201801-12
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.