Back

HIGH

evolution: TNEF attachment decoder input sanitization errors (oCERT-2009-013)

Published May 26, 2021

Description

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 26, 2021
Updated Aug 7, 2024
Reserved Oct 16, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 7, 2009
ENISA EUVD
Assigner redhat
Published May 26, 2021
Updated Aug 7, 2024
Exploited since n/a
EUVD-2009-3694