ALT-PU-2017-1265-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2017-6298
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "1 of 9. Null Pointer Deref / calloc return value not checked."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6299
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infinite Loop / DoS in the TNEFFillMapi function in lib/ytnef.c."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6300
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "3 of 9. Buffer Overflow in version field in lib/tnef-types.h."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6301
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "4 of 9. Out of Bounds Reads."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6302
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "5 of 9. Integer Overflow."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6303
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "6 of 9. Invalid Write and Integer Overflow."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6304
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "7 of 9. Out of Bounds read."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6305
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6306
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilename function in settings.c."
- DSA-3846
- DSA-3846
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- http://www.openwall.com/lists/oss-security/2017/02/15/4
- 96423
- 96423
- https://github.com/Yeraze/ytnef/pull/27
- https://github.com/Yeraze/ytnef/pull/27
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/
Modified: 2024-11-21
CVE-2017-6800
An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef.
- DSA-3846
- DSA-3846
- https://github.com/Yeraze/ytnef/commit/f98f5d4adc1c4bd4033638f6167c1bb95d642f89
- https://github.com/Yeraze/ytnef/commit/f98f5d4adc1c4bd4033638f6167c1bb95d642f89
- https://github.com/Yeraze/ytnef/issues/28
- https://github.com/Yeraze/ytnef/issues/28
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be
Modified: 2024-11-21
CVE-2017-6801
An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.
Modified: 2024-11-21
CVE-2017-6802
An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.
- DSA-3846
- DSA-3846
- https://github.com/Yeraze/ytnef/commit/22f8346c8d4f0020a40d9f258fdb3bfc097359cc
- https://github.com/Yeraze/ytnef/commit/22f8346c8d4f0020a40d9f258fdb3bfc097359cc
- https://github.com/Yeraze/ytnef/issues/34
- https://github.com/Yeraze/ytnef/issues/34
- FEDORA-2019-7d7083b8be
- FEDORA-2019-7d7083b8be