ALT-PU-2019-3194-1
Closed vulnerabilities
Published: 2019-11-11
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-18849
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.
Severity: MEDIUM (5.5)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References:
- https://github.com/verdammelt/tnef/compare/1.4.17...1.4.18
- https://github.com/verdammelt/tnef/compare/1.4.17...1.4.18
- https://github.com/verdammelt/tnef/pull/40
- https://github.com/verdammelt/tnef/pull/40
- [debian-lts-announce] 20191129 [SECURITY] [DLA 2005-1] tnef security update
- [debian-lts-announce] 20191129 [SECURITY] [DLA 2005-1] tnef security update
- [debian-lts-announce] 20210823 [SECURITY] [DLA 2748-1] tnef security update
- [debian-lts-announce] 20210823 [SECURITY] [DLA 2748-1] tnef security update
- FEDORA-2019-5f14b810f8
- FEDORA-2019-5f14b810f8
- FEDORA-2019-815807c020
- FEDORA-2019-815807c020
- USN-4524-1
- USN-4524-1