CVE-2017-6801Out-of-bounds Read in Libytnef

CWE-125Out-of-bounds Read12 documents6 sources
Severity
7.5HIGHNVD
OSV7.8
EPSS
0.5%
top 33.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMay 14

Description

An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

debiandebian/libytnef< libytnef 1.9.2-1 (bookworm)

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xg55-jq33-cf6c: An issue was discovered in ytnef before 12022-05-14
OSV
libytnef vulnerabilities2020-11-03
OSV
CVE-2017-6801: An issue was discovered in ytnef before 12017-03-10

📋Vendor Advisories

3
Ubuntu
Yerase's TNEF vulnerabilities2020-11-03
Ubuntu
libytnef vulnerabilities2017-05-15
Debian
CVE-2017-6801: libytnef - An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bound...2017

💬Community

5
Bugzilla
CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 CVE-2017-9058 CVE-2017-9146 ytnef: Multiple vulnerabilities fixed in 1.9.2 version2017-03-13
Bugzilla
CVE-2017-6298 CVE-2017-6299 CVE-2017-6300 CVE-2017-6301 CVE-2017-6302 CVE-2017-6303 CVE-2017-6304 CVE-2017-6305 CVE-2017-6306 CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 libytnef: various flaws [epel-al2017-02-16
Bugzilla
CVE-2017-6298 CVE-2017-6299 CVE-2017-6300 CVE-2017-6301 CVE-2017-6302 CVE-2017-6303 CVE-2017-6304 CVE-2017-6305 CVE-2017-6306 CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 ytnef: various flaws [fedora-all2017-02-16
Bugzilla
CVE-2017-6298 CVE-2017-6299 CVE-2017-6300 CVE-2017-6301 CVE-2017-6302 CVE-2017-6303 CVE-2017-6304 CVE-2017-6305 CVE-2017-6306 CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 libytnef: various flaws [fedora-2017-02-16
Bugzilla
CVE-2017-6298 CVE-2017-6299 CVE-2017-6300 CVE-2017-6301 CVE-2017-6302 CVE-2017-6303 CVE-2017-6304 CVE-2017-6305 CVE-2017-6306 CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 ytnef: various flaws [epel-all]2017-02-16