CVE-2017-7523

EUVD-2017-16540
Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hijack of the process running with administrative privileges triggered by specially crafted input string.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Affected Products (NVD)
VendorProductVersion
cygwincygwin
1.7.2
cygwincygwin
1.7.3
cygwincygwin
1.7.5
cygwincygwin
1.7.6
cygwincygwin
1.7.7
cygwincygwin
1.7.8
cygwincygwin
1.7.9
cygwincygwin
1.7.10
cygwincygwin
1.7.11
cygwincygwin
1.7.12
cygwincygwin
1.7.13
cygwincygwin
1.7.14
cygwincygwin
1.7.15
cygwincygwin
1.7.16
cygwincygwin
1.7.17
cygwincygwin
1.7.18
cygwincygwin
1.7.19
cygwincygwin
1.7.21
cygwincygwin
1.7.22
cygwincygwin
1.7.23
cygwincygwin
1.7.24
cygwincygwin
1.7.25
cygwincygwin
1.7.26
cygwincygwin
1.7.27
cygwincygwin
1.7.28
cygwincygwin
1.7.29
cygwincygwin
1.7.31
cygwincygwin
1.7.32
cygwincygwin
1.7.33
cygwincygwin
1.7.34
cygwincygwin
1.7.35
cygwincygwin
1.8.0
𝑥
= Vulnerable software versions