668
VMScore

CVE-2017-9058

Published: 18/05/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In libytnef in ytnef up to and including 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ytnef project ytnef

canonical ubuntu linux 14.04

Vendor Advisories

Several security issues were fixed in libytnef ...
Debian Bug report logs - #870196 libytnef: CVE-2017-9470: NULL pointer dereference in MAPIPrint Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 30 Jul 2017 20:39:01 UTC Severity: important Tags: fixed-upstream, se ...
Debian Bug report logs - #870816 libytnef: CVE-2017-12142: SEGV in ytnefc in SwapDWord Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 5 Aug 2017 13:36:01 UTC Severity: important Tags: fixed-upstream, security, ...
Debian Bug report logs - #870194 libytnef: CVE-2017-9471: heap-based-buffer overflow in SwapWord Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 30 Jul 2017 20:36:02 UTC Severity: important Tags: fixed-upstream, s ...
Debian Bug report logs - #870192 libytnef: CVE-2017-9474: heap-based buffer overflow in DecompressRTF Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 30 Jul 2017 20:33:01 UTC Severity: important Tags: fixed-upstre ...
Debian Bug report logs - #862556 CVE-2017-9058: Heap-based buffer overflow due to incorrect boundary checking Package: libytnef; Maintainer for libytnef is Ricardo Mones <mones@debianorg>; Reported by: "bingosxs" <bingosxs@qqcom> Date: Sun, 14 May 2017 15:06:02 UTC Severity: serious Tags: security Found in version ...
Debian Bug report logs - #870815 libytnef: CVE-2017-12141: heap-buffer-overflow Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 5 Aug 2017 13:33:02 UTC Severity: grave Tags: fixed-upstream, security, upstream Fo ...
Debian Bug report logs - #870817 libytnef: CVE-2017-12144 Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 5 Aug 2017 13:36:04 UTC Severity: normal Tags: fixed-upstream, security, upstream Found in version libytn ...
A heap-buffer-overflow vulnerability has been found in the libytnef in the lib/ytnefc module ...