An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade tnef | May 29, 2017 | May 12, 2017 |
| Gentoo Linux | — | Upgrade net-mail/tnef. | Oct 30, 2017 | May 12, 2017 |
| Suse | — | Upgrade tnefUpgrade tnef-debugsourceUpgrade tnef-debuginfo | Nov 27, 2017 | May 12, 2017 |
| Ubuntu | — | Upgrade tnef | Nov 19, 2024 | May 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub