ALT-BU-2018-3366-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-12141
In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
- https://github.com/Yeraze/ytnef/issues/50
- https://github.com/Yeraze/ytnef/issues/50
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://somevulnsofadlab.blogspot.com/2017/07/ytnefheap-buffer-overflow-in.html
- https://somevulnsofadlab.blogspot.com/2017/07/ytnefheap-buffer-overflow-in.html
- USN-3667-1
- USN-3667-1
Modified: 2024-11-21
CVE-2017-12142
In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
- https://github.com/Yeraze/ytnef/issues/49
- https://github.com/Yeraze/ytnef/issues/49
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://somevulnsofadlab.blogspot.com/2017/07/ytnefinvalid-memory-read-in-swapdword.html
- https://somevulnsofadlab.blogspot.com/2017/07/ytnefinvalid-memory-read-in-swapdword.html
Modified: 2024-11-21
CVE-2017-12144
In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
- 100098
- 100098
- https://github.com/Yeraze/ytnef/issues/51
- https://github.com/Yeraze/ytnef/issues/51
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://somevulnsofadlab.blogspot.com/2017/07/ytnefallocation-failed-in-tneffillmapi.html
- https://somevulnsofadlab.blogspot.com/2017/07/ytnefallocation-failed-in-tneffillmapi.html
Modified: 2024-11-21
CVE-2017-9058
In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.
Modified: 2024-11-21
CVE-2017-9146
The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted tnef file.
Modified: 2024-11-21
CVE-2017-9470
In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Modified: 2024-11-21
CVE-2017-9471
In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Modified: 2024-11-21
CVE-2017-9472
In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Modified: 2024-11-21
CVE-2017-9473
In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
Modified: 2024-11-21
CVE-2017-9474
In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.