1 |
type: security |
2 |
subject: Updated tnef packages fix security vulnerability |
3 |
CVE: |
4 |
- CVE-2017-6307 |
5 |
- CVE-2017-6308 |
6 |
- CVE-2017-6309 |
7 |
- CVE-2017-6310 |
8 |
src: |
9 |
5: |
10 |
core: |
11 |
- tnef-1.4.9-4.1.mga5 |
12 |
description: | |
13 |
An issue was discovered in tnef before 1.4.13. Two OOB Writes have been |
14 |
identified in src/mapi_attr.c:mapi_attr_read(). These might lead to |
15 |
invalid read and write operations, controlled by an attacker. |
16 |
(CVE-2017-6307) |
17 |
|
18 |
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, |
19 |
which can lead to Heap Overflows, have been identified in the functions |
20 |
that wrap memory allocation. (CVE-2017-6308) |
21 |
|
22 |
An issue was discovered in tnef before 1.4.13. Two type confusions have |
23 |
been identified in the parse_file() function. These might lead to invalid |
24 |
read and write operations, controlled by an attacker. (CVE-2017-6309) |
25 |
|
26 |
An issue was discovered in tnef before 1.4.13. Four type confusions have |
27 |
been identified in the file_add_mapi_attrs() function. These might lead to |
28 |
invalid read and write operations, controlled by an attacker. |
29 |
(CVE-2017-6310) |
30 |
references: |
31 |
- https://bugs.mageia.org/show_bug.cgi?id=20343 |
32 |
- http://openwall.com/lists/oss-security/2017/02/23/17 |
33 |
- https://www.debian.org/security/2017/dsa-3798 |
34 |
ID: MGASA-2017-0083 |