Vulnerabilities
Vulnerable Software
Ytnef Project:  >> Ytnef  >> 1.9.3  Security Vulnerabilities
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.
CVSS Score
7.8
EPSS Score
0.008
Published
2021-05-26
In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.
CVSS Score
7.8
EPSS Score
0.008
Published
2021-03-04
In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.
CVSS Score
7.8
EPSS Score
0.021
Published
2021-03-04
ytnef has directory traversal
CVSS Score
9.8
EPSS Score
0.004
Published
2019-10-29


Contact Us

Shodan ® - All rights reserved