7.8
CVSSv3

CVE-2017-6304

Published: 24/02/2017 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in ytnef prior to 1.9.1. This is related to a patch described as "7 of 9. Out of Bounds read."

Vulnerable Product Search on Vulmon Subscribe to Product

ytnef project ytnef

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

libytnef could be made to crash or run programs as your login if it opened a specially crafted file ...
Several issues were discovered in libytnef, a library used to decode application/ms-tnef e-mail attachments Multiple heap overflows, out-of-bound writes and reads, NULL pointer dereferences and infinite loops could be exploited by tricking a user into opening a maliciously crafted winmaildat file For the stable distribution (jessie), these probl ...