Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cq6j-h35c-x8gr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

EPSS

Процентиль: 77%
0.01023
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

CVSS3: 5.5
nvd
около 6 лет назад

In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

CVSS3: 5.5
debian
около 6 лет назад

In tnef before 1.4.18, an attacker may be able to write to the victim' ...

EPSS

Процентиль: 77%
0.01023
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-125