Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3404

Опубликовано: 04 мар. 2021
Источник: debian

Описание

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libytneffixed1.9.3-3package
libytnefno-dsabusterpackage
libytnefno-dsastretchpackage

Примечания

  • https://github.com/Yeraze/ytnef/issues/86

  • https://github.com/Yeraze/ytnef/pull/88

  • https://github.com/Yeraze/ytnef/commit/f9ff4a203b8c155d51a208cadadb62f224fba715

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 5 лет назад

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.

CVSS3: 7.8
nvd
почти 5 лет назад

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.

CVSS3: 7.8
github
больше 3 лет назад

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.