CVE-2017-9146
published 2017-05-22CVE-2017-9146: The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which…
PriorityP338high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.39%
82.0th percentile
The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted tnef file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libytnef | < libytnef 1.9.3-1 (bookworm) | libytnef 1.9.3-1 (bookworm) |
| ytnef_project | ytnef | <= 1.9.2 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat6.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-798c-jx77-ccgp: The TNEFFillMapi function in lib/ytnef
ghsa_unreviewed·2022-05-14
CVE-2017-9146 [HIGH] CWE-119 GHSA-798c-jx77-ccgp: The TNEFFillMapi function in lib/ytnef
The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted tnef file.
OSV
libytnef vulnerabilities
osv·2018-05-31·CVSS 5.5
CVE-2017-12141 [MEDIUM] libytnef vulnerabilities
libytnef vulnerabilities
It was discovered that libytnef incorrectly handled certain files.
An attacker could possibly use this to cause a denial of service.
(CVE-2017-12141, CVE-2017-9146, CVE-2017-9471, CVE-2017-9473)
It was discovered that libytnef incorrectly handled certain files.
An attacker could possibly use this to access sensitive information.
(CVE-2017-9058)
OSV
CVE-2017-9146: The TNEFFillMapi function in lib/ytnef
osv·2017-05-22·CVSS 8.8
CVE-2017-9146 [HIGH] CVE-2017-9146: The TNEFFillMapi function in lib/ytnef
The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted tnef file.
Ubuntu
libytnef vulnerabilities
vendor_ubuntu·2018-05-31·CVSS 5.5
CVE-2017-12141 [MEDIUM] libytnef vulnerabilities
Title: libytnef vulnerabilities
Summary: Several security issues were fixed in libytnef.
It was discovered that libytnef incorrectly handled certain files.
An attacker could possibly use this to cause a denial of service.
(CVE-2017-12141, CVE-2017-9146, CVE-2017-9471, CVE-2017-9473)
It was discovered that libytnef incorrectly handled certain files.
An attacker could possibly use this to access sensitive information.
(CVE-2017-9058)
Instructions: After a standard system update you need to restart applications using libytnef, such as Evolution, to make all the necessary changes.
Red Hat
exiv2: out-of-bounds read in Exiv2::IptcData::printStructure in image.cpp
vendor_redhat·2018-03-28·CVSS 6.5
CVE-2018-9146 [MEDIUM] CWE-125 exiv2: out-of-bounds read in Exiv2::IptcData::printStructure in image.cpp
exiv2: out-of-bounds read in Exiv2::IptcData::printStructure in image.cpp
[REJECTED CVE] An integer underflow, leading to heap-based out-of-bound read, was found in the way Exiv2 library prints IPTC Photo Metadata embedded in an image. By persuading a victim to open a crafted image, a remote attacker could crash the application or possibly retrieve a portion of memory.
Statement: This flaw was found to be a duplicate of CVE-2017-17724. Please see https://access.redhat.com/security/cve/CVE-2017-17724 for information about affected products and security errata.
Package: exiv2 (Red Hat Enterprise Linux 6) - Not affected
Package: exiv2 (Red Hat Enterprise Linux 7) - Not affected
Package: exiv2 (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2017-9146: libytnef - The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does...
vendor_debian·2017·CVSS 8.8
CVE-2017-9146 [HIGH] CVE-2017-9146: libytnef - The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does...
The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted tnef file.
Scope: local
bookworm: resolved (fixed in 1.9.3-1)
bullseye: resolved (fixed in 1.9.3-1)
forky: resolved (fixed in 1.9.3-1)
sid: resolved (fixed in 1.9.3-1)
trixie: resolved (fixed in 1.9.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-9146 exiv2: out-of-bounds read in Exiv2::IptcData::printStructure in image.cpp
bugzilla·2018-04-05·CVSS 6.5
CVE-2018-9146 [MEDIUM] CVE-2018-9146 exiv2: out-of-bounds read in Exiv2::IptcData::printStructure in image.cpp
CVE-2018-9146 exiv2: out-of-bounds read in Exiv2::IptcData::printStructure in image.cpp
A flaw was found in Exiv2 0.26, there is an out-of-bounds read in Exiv2::IptcData::printStructure in image.cpp, a different vulnerability than CVE-2017-17724. It could result in denial of service or information disclosure.
References:
https://bugzilla.novell.com/show_bug.cgi?id=108789
https://github.com/Exiv2/exiv2/issues/254
https://github.com/xiaoqx/pocs/tree/master/exiv2
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1564279]
---
This CVE has been rejected by MITRE as a dup of CVE-2017-17724 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-9146)
*** This bug has been marked as a duplicate of bug 1545237 ***
---
Statement:
This flaw was found to be
Bugzilla
CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 CVE-2017-9058 CVE-2017-9146 ytnef: Multiple vulnerabilities fixed in 1.9.2 version
bugzilla·2017-03-13·CVSS 7.5
CVE-2017-6800 [HIGH] CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 CVE-2017-9058 CVE-2017-9146 ytnef: Multiple vulnerabilities fixed in 1.9.2 version
CVE-2017-6800 CVE-2017-6801 CVE-2017-6802 CVE-2017-9058 CVE-2017-9146 ytnef: Multiple vulnerabilities fixed in 1.9.2 version
CVE-2017-6802 - An issue was discovered in ytnef before 1.9.2. There is a potential
heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.
Upstream bug:
https://github.com/Yeraze/ytnef/issues/34
CVE-2017-6801 - An issue was discovered in ytnef before 1.9.2. There is a potential
out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.
Upstream patch:
https://github.com/Yeraze/ytnef/commit/3cb0f914d6427073f262e1b2b5fd973e3043cdf7
CVE-2017-6800 - An issue was discovered in ytnef before 1.9.2. An invalid memory access
(heap-based buffer over-read) can occur during handling of LONG data types, related t
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862707https://github.com/Yeraze/ytnef/issues/47https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LFJWMUEUC4ILH2HEOCYVVLQT654ZMCGQ/https://usn.ubuntu.com/3667-1/http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862707https://github.com/Yeraze/ytnef/issues/47https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LFJWMUEUC4ILH2HEOCYVVLQT654ZMCGQ/https://usn.ubuntu.com/3667-1/
2017-05-22
Published