Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3403

Опубликовано: 04 мар. 2021
Источник: debian

Описание

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libytneffixed1.9.3-3package
libytnefno-dsabusterpackage
libytnefno-dsastretchpackage

Примечания

  • https://github.com/Yeraze/ytnef/issues/85

  • https://github.com/Yeraze/ytnef/pull/87

  • https://github.com/Yeraze/ytnef/commit/f2380a53fb84d370eaf6e6c3473062c54c57fac7

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 5 лет назад

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.

CVSS3: 7.8
nvd
почти 5 лет назад

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.

CVSS3: 7.8
github
больше 3 лет назад

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.