7.5
CVSSv3

CVE-2017-6802

Published: 10/03/2017 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in ytnef prior to 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.

Vulnerable Product Search on Vulmon Subscribe to Product

ytnef project ytnef

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

libytnef could be made to crash or run programs as your login if it opened a specially crafted file ...
Several issues were discovered in libytnef, a library used to decode application/ms-tnef e-mail attachments Multiple heap overflows, out-of-bound writes and reads, NULL pointer dereferences and infinite loops could be exploited by tricking a user into opening a maliciously crafted winmaildat file For the stable distribution (jessie), these probl ...