PublicDateAtUSN: 2017-05-22 Candidate: CVE-2017-9146 PublicDate: 2017-05-22 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9146 https://ubuntu.com/security/notices/USN-3667-1 Description: The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted tnef file. Ubuntu-Description: Notes: Bugs: https://github.com/Yeraze/ytnef/issues/47 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862707 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_libytnef: upstream: https://github.com/Yeraze/ytnef/commit/c576639e7e6bd9c7de0a288b9f94590d34ac9215 upstream_libytnef: released (1.9.3-1) precise/esm_libytnef: DNE trusty_libytnef: released (1.5-6ubuntu0.2) trusty/esm_libytnef: DNE (trusty was released [1.5-6ubuntu0.2]) vivid/stable-phone-overlay_libytnef: DNE vivid/ubuntu-core_libytnef: DNE xenial_libytnef: ignored (end of standard support, was needed) yakkety_libytnef: ignored (reached end-of-life) zesty_libytnef: ignored (reached end-of-life) artful_libytnef: ignored (reached end-of-life) bionic_libytnef: needed cosmic_libytnef: ignored (reached end-of-life) disco_libytnef: not-affected (1.9.3-1) eoan_libytnef: not-affected (1.9.3-1) focal_libytnef: not-affected (1.9.3-1) groovy_libytnef: not-affected (1.9.3-1) hirsute_libytnef: not-affected (1.9.3-1) impish_libytnef: not-affected (1.9.3-1) jammy_libytnef: not-affected (1.9.3-1) devel_libytnef: not-affected (1.9.3-1)