Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-3721

Опубликовано: 26 мая 2021
Источник: debian
EPSS Низкий

Описание

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ytnefremovedpackage
ytnefno-dsalennypackage

Примечания

  • http://www.ocert.org/advisories/ocert-2009-013.html

  • This doesn't affect Evolution, the TNEF plugin is external

EPSS

Процентиль: 73%
0.00781
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.

redhat
больше 16 лет назад

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.

CVSS3: 7.8
nvd
больше 4 лет назад

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.

github
почти 4 года назад

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.

EPSS

Процентиль: 73%
0.00781
Низкий