CVE-2010-5109Off-by-one Error in Fedora

CWE-1895 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
1.2%
top 20.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 5
Latest updateMay 17

Description

Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remote attackers to cause a denial of service (crash) via a crafted TNEF file, which triggers a buffer overflow.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

Debianclaws-mail/claws-mail< 3.11.1-2+3

Also affects: Fedora 16, 17

🔴Vulnerability Details

3
GHSA
GHSA-gm6c-c76r-gr4j: Off-by-one error in the DecompressRTF function in ytnef2022-05-17
CVEList
CVE-2010-5109: Off-by-one error in the DecompressRTF function in ytnef2014-05-05
OSV
CVE-2010-5109: Off-by-one error in the DecompressRTF function in ytnef2014-05-05

📋Vendor Advisories

1
Debian
CVE-2010-5109: claws-mail - Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Strea...2010
CVE-2010-5109 — Off-by-one Error in Fedora | cvebase