ISOMAN

CVE

CVE-2017-9058

In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.

Severity
CRITICAL
CVSS
9.8
Published
Modified

Linked Releases

References

  1. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862556
  2. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LFJWMUEUC4ILH2HEOCYVVLQT654ZMCGQ/
  3. https://usn.ubuntu.com/3667-1/
  4. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862556
  5. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LFJWMUEUC4ILH2HEOCYVVLQT654ZMCGQ/
  6. https://usn.ubuntu.com/3667-1/