CVE-2017-7523

Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hijack of the process running with administrative privileges triggered by specially crafted input string.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
cygwincygwin
1.7.2
cygwincygwin
1.7.3
cygwincygwin
1.7.5
cygwincygwin
1.7.6
cygwincygwin
1.7.7
cygwincygwin
1.7.8
cygwincygwin
1.7.9
cygwincygwin
1.7.10
cygwincygwin
1.7.11
cygwincygwin
1.7.12
cygwincygwin
1.7.13
cygwincygwin
1.7.14
cygwincygwin
1.7.15
cygwincygwin
1.7.16
cygwincygwin
1.7.17
cygwincygwin
1.7.18
cygwincygwin
1.7.19
cygwincygwin
1.7.21
cygwincygwin
1.7.22
cygwincygwin
1.7.23
cygwincygwin
1.7.24
cygwincygwin
1.7.25
cygwincygwin
1.7.26
cygwincygwin
1.7.27
cygwincygwin
1.7.28
cygwincygwin
1.7.29
cygwincygwin
1.7.31
cygwincygwin
1.7.32
cygwincygwin
1.7.33
cygwincygwin
1.7.34
cygwincygwin
1.7.35
cygwincygwin
1.8.0
𝑥
= Vulnerable software versions