PublicDateAtUSN: 2017-03-10 Candidate: CVE-2017-6801 PublicDate: 2017-03-10 10:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6801 https://github.com/Yeraze/ytnef/commit/3cb0f914d6427073f262e1b2b5fd973e3043cdf7 https://ubuntu.com/security/notices/USN-3288-1 https://ubuntu.com/security/notices/USN-4615-1 Description: An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Hanno Böck Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_libytnef: upstream: https://github.com/Yeraze/ytnef/commit/3cb0f914d6427073f262e1b2b5fd973e3043cdf7 upstream_libytnef: released (1.9.2-1) precise_libytnef: ignored (reached end-of-life) precise/esm_libytnef: DNE (precise was needed) trusty_libytnef: released (1.5-6ubuntu0.1) trusty/esm_libytnef: DNE (trusty was released [1.5-6ubuntu0.1]) vivid/stable-phone-overlay_libytnef: DNE vivid/ubuntu-core_libytnef: DNE xenial_libytnef: released (1.5-9ubuntu0.1) yakkety_libytnef: ignored (reached end-of-life) zesty_libytnef: not-affected (1.9.2-1) artful_libytnef: not-affected (1.9.2-1) bionic_libytnef: not-affected (1.9.2-1) cosmic_libytnef: not-affected (1.9.2-1) disco_libytnef: not-affected (1.9.2-1) eoan_libytnef: not-affected (1.9.2-1) focal_libytnef: not-affected (1.9.2-1) groovy_libytnef: not-affected (1.9.2-1) devel_libytnef: not-affected (1.9.2-1)