ALT-BU-2017-2981-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-9461
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
- 99455
- 99455
- RHSA-2017:1950
- RHSA-2017:1950
- RHSA-2017:2338
- RHSA-2017:2338
- RHSA-2017:2778
- RHSA-2017:2778
- https://bugs.debian.org/864291
- https://bugs.debian.org/864291
- https://bugzilla.samba.org/show_bug.cgi?id=12572
- https://bugzilla.samba.org/show_bug.cgi?id=12572
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=10c3e3923022485c720f322ca4f0aca5d7501310
- https://git.samba.org/?p=samba.git%3Ba=commit%3Bh=10c3e3923022485c720f322ca4f0aca5d7501310
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-6298
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "1 of 9. Null Pointer Deref / calloc return value not checked."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6299
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infinite Loop / DoS in the TNEFFillMapi function in lib/ytnef.c."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6300
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "3 of 9. Buffer Overflow in version field in lib/tnef-types.h."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6301
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "4 of 9. Out of Bounds Reads."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6302
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "5 of 9. Integer Overflow."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6303
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "6 of 9. Invalid Write and Integer Overflow."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6304
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "7 of 9. Out of Bounds read."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6305
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6306
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilename function in settings.c."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6800
An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef.
- DSA-3846
- DSA-3846
- https://github.com/Yeraze/ytnef/commit/f98f5d4adc1c4bd4033638f6167c1bb95d642f89
- https://github.com/Yeraze/ytnef/commit/f98f5d4adc1c4bd4033638f6167c1bb95d642f89
- https://github.com/Yeraze/ytnef/issues/28
- https://github.com/Yeraze/ytnef/issues/28
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
Modified: 2024-11-21
CVE-2017-6801
An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.
Modified: 2024-11-21
CVE-2017-6802
An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.
- DSA-3846
- DSA-3846
- https://github.com/Yeraze/ytnef/commit/22f8346c8d4f0020a40d9f258fdb3bfc097359cc
- https://github.com/Yeraze/ytnef/commit/22f8346c8d4f0020a40d9f258fdb3bfc097359cc
- https://github.com/Yeraze/ytnef/issues/34
- https://github.com/Yeraze/ytnef/issues/34
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-6307
An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, controlled by an attacker.
- DSA-3798
- DSA-3798
- 96427
- 96427
- https://github.com/verdammelt/tnef/blob/master/ChangeLog
- https://github.com/verdammelt/tnef/blob/master/ChangeLog
- https://github.com/verdammelt/tnef/commit/1a17af1ed0c791aec44dbdc9eab91218cc1e335a
- https://github.com/verdammelt/tnef/commit/1a17af1ed0c791aec44dbdc9eab91218cc1e335a
- GLSA-201708-02
- GLSA-201708-02
- https://www.x41-dsec.de/lab/advisories/x41-2017-004-tnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-004-tnef/
Modified: 2024-11-21
CVE-2017-6308
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
- DSA-3798
- DSA-3798
- 96427
- 96427
- https://github.com/verdammelt/tnef/blob/master/ChangeLog
- https://github.com/verdammelt/tnef/blob/master/ChangeLog
- https://github.com/verdammelt/tnef/commit/c5044689e50039635e7700fe2472fd632ac77176
- https://github.com/verdammelt/tnef/commit/c5044689e50039635e7700fe2472fd632ac77176
- GLSA-201708-02
- GLSA-201708-02
- https://www.x41-dsec.de/lab/advisories/x41-2017-004-tnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-004-tnef/
Modified: 2024-11-21
CVE-2017-6309
An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.
- DSA-3798
- DSA-3798
- 96427
- 96427
- https://github.com/verdammelt/tnef/blob/master/ChangeLog
- https://github.com/verdammelt/tnef/blob/master/ChangeLog
- https://github.com/verdammelt/tnef/commit/8dccf79857ceeb7a6d3e42c1e762e7b865d5344d
- https://github.com/verdammelt/tnef/commit/8dccf79857ceeb7a6d3e42c1e762e7b865d5344d
- GLSA-201708-02
- GLSA-201708-02
- https://www.x41-dsec.de/lab/advisories/x41-2017-004-tnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-004-tnef/
Modified: 2024-11-21
CVE-2017-6310
An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.
- DSA-3798
- DSA-3798
- 96427
- 96427
- https://github.com/verdammelt/tnef/blob/master/ChangeLog
- https://github.com/verdammelt/tnef/blob/master/ChangeLog
- https://github.com/verdammelt/tnef/commit/8dccf79857ceeb7a6d3e42c1e762e7b865d5344d
- https://github.com/verdammelt/tnef/commit/8dccf79857ceeb7a6d3e42c1e762e7b865d5344d
- GLSA-201708-02
- GLSA-201708-02
- https://www.x41-dsec.de/lab/advisories/x41-2017-004-tnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-004-tnef/