HIGH
An issue was discovered in ytnef before 1.9.1
Published Feb 24, 2017
7.8
HIGHCVSS 3.0
EPSS 1.22%
Description
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."
Affected products
No data.
Configuration 1
- ≤ 1.9
Configuration 2
OR
- 8.0
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- http://www.debian.org/security/2017/dsa-3846 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.openwall.com/lists/oss-security/2017/02/15/4 x_refsource_MISCMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/96423 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://github.com/Yeraze/ytnef/pull/27 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LFJWMUEUC4ILH2HEOCYVVLQT654ZMCGQ/ vendor-advisoryx_refsource_FEDORA
- https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/ x_refsource_MISCPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.debian.org/security/2017/dsa-3846 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2017/02/15/4 | x_refsource_MISCMailing ListPatchThird Party Advisory | |
| http://www.securityfocus.com/bid/96423 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://github.com/Yeraze/ytnef/pull/27 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LFJWMUEUC4ILH2HEOCYVVLQT654ZMCGQ/ | vendor-advisoryx_refsource_FEDORA | |
| https://www.x41-dsec.de/lab/advisories/x41-2017-002-ytnef/ | x_refsource_MISCPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 24, 2017
Updated Aug 5, 2024
Reserved Feb 23, 2017
Link CVE-2017-6305
CISA Vulnrichment
Updated n/a