5.5
CVSSv3

CVE-2017-9471

Published: 07/06/2017 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote malicious users to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ytnef project ytnef 1.9.2

canonical ubuntu linux 14.04

Vendor Advisories

Several security issues were fixed in libytnef ...
Debian Bug report logs - #870816 libytnef: CVE-2017-12142: SEGV in ytnefc in SwapDWord Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 5 Aug 2017 13:36:01 UTC Severity: important Tags: fixed-upstream, security, ...
Debian Bug report logs - #870194 libytnef: CVE-2017-9471: heap-based-buffer overflow in SwapWord Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 30 Jul 2017 20:36:02 UTC Severity: important Tags: fixed-upstream, s ...
Debian Bug report logs - #870192 libytnef: CVE-2017-9474: heap-based buffer overflow in DecompressRTF Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 30 Jul 2017 20:33:01 UTC Severity: important Tags: fixed-upstre ...
Debian Bug report logs - #870196 libytnef: CVE-2017-9470: NULL pointer dereference in MAPIPrint Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 30 Jul 2017 20:39:01 UTC Severity: important Tags: fixed-upstream, se ...
Debian Bug report logs - #870815 libytnef: CVE-2017-12141: heap-buffer-overflow Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 5 Aug 2017 13:33:02 UTC Severity: grave Tags: fixed-upstream, security, upstream Fo ...
Debian Bug report logs - #870817 libytnef: CVE-2017-12144 Package: src:libytnef; Maintainer for src:libytnef is Ricardo Mones <mones@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 5 Aug 2017 13:36:04 UTC Severity: normal Tags: fixed-upstream, security, upstream Found in version libytn ...