CVE-2017-7523

Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hijack of the process running with administrative privileges triggered by specially crafted input string.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
cygwincygwin
1.7.2
cygwincygwin
1.7.3
cygwincygwin
1.7.5
cygwincygwin
1.7.6
cygwincygwin
1.7.7
cygwincygwin
1.7.8
cygwincygwin
1.7.9
cygwincygwin
1.7.10
cygwincygwin
1.7.11
cygwincygwin
1.7.12
cygwincygwin
1.7.13
cygwincygwin
1.7.14
cygwincygwin
1.7.15
cygwincygwin
1.7.16
cygwincygwin
1.7.17
cygwincygwin
1.7.18
cygwincygwin
1.7.19
cygwincygwin
1.7.21
cygwincygwin
1.7.22
cygwincygwin
1.7.23
cygwincygwin
1.7.24
cygwincygwin
1.7.25
cygwincygwin
1.7.26
cygwincygwin
1.7.27
cygwincygwin
1.7.28
cygwincygwin
1.7.29
cygwincygwin
1.7.31
cygwincygwin
1.7.32
cygwincygwin
1.7.33
cygwincygwin
1.7.34
cygwincygwin
1.7.35
cygwincygwin
1.8.0
𝑥
= Vulnerable software versions