FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

tnef -- Invalid read and write operations, controlled by an attacker

Affected packages
tnef <= 1.4.12

Details

VuXML ID 70cf37c8-939b-11ef-87ad-a8a15998b5cb
Discovery 2017-02-24
Entry 2024-10-26

cve@mitre.org reports:

CVE-2017-6307: An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, controlled by an attacker.

CVE-2017-6308: An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.

CVE-2017-6309: An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.

CVE-2017-6310: An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.

References

CVE Name CVE-2017-6307
CVE Name CVE-2017-6308
CVE Name CVE-2017-6309
CVE Name CVE-2017-6310
URL https://nvd.nist.gov/vuln/detail/CVE-2017-6307
URL https://nvd.nist.gov/vuln/detail/CVE-2017-6308
URL https://nvd.nist.gov/vuln/detail/CVE-2017-6309
URL https://nvd.nist.gov/vuln/detail/CVE-2017-6310