CVE-2017-6800Out-of-bounds Read in Libytnef

Severity
7.5HIGHNVD
OSV7.8CISA6.5
EPSS
0.5%
top 32.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMay 14

Description

An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

debiandebian/libytnef< libytnef 1.9.2-1 (bookworm)

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9v9m-hrxh-m74p: An issue was discovered in ytnef before 12022-05-14
OSV
libytnef vulnerabilities2020-11-03
OSV
CVE-2017-6800: An issue was discovered in ytnef before 12017-03-10

📋Vendor Advisories

6
CISA
Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability2022-03-03
Ubuntu
Yerase's TNEF vulnerabilities2020-11-03
Cisco
Cisco IOS Software for Cisco Catalyst 6800 Series Switches VPLS Denial of Service Vulnerability2017-09-27
Ubuntu
libytnef vulnerabilities2017-05-15
Debian
CVE-2017-6800: libytnef - An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-ba...2017

💬Community

5
Bugzilla
CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 CVE-2017-9058 CVE-2017-9146 ytnef: Multiple vulnerabilities fixed in 1.9.2 version2017-03-13
Bugzilla
CVE-2017-6298 CVE-2017-6299 CVE-2017-6300 CVE-2017-6301 CVE-2017-6302 CVE-2017-6303 CVE-2017-6304 CVE-2017-6305 CVE-2017-6306 CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 libytnef: various flaws [epel-al2017-02-16
Bugzilla
CVE-2017-6298 CVE-2017-6299 CVE-2017-6300 CVE-2017-6301 CVE-2017-6302 CVE-2017-6303 CVE-2017-6304 CVE-2017-6305 CVE-2017-6306 CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 ytnef: various flaws [fedora-all2017-02-16
Bugzilla
CVE-2017-6298 CVE-2017-6299 CVE-2017-6300 CVE-2017-6301 CVE-2017-6302 CVE-2017-6303 CVE-2017-6304 CVE-2017-6305 CVE-2017-6306 CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 libytnef: various flaws [fedora-2017-02-16
Bugzilla
CVE-2017-6298 CVE-2017-6299 CVE-2017-6300 CVE-2017-6301 CVE-2017-6302 CVE-2017-6303 CVE-2017-6304 CVE-2017-6305 CVE-2017-6306 CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 ytnef: various flaws [epel-all]2017-02-16