CVE-2017-6298: Null Pointer Dereference
Published Feb 24, 2017
·Updated
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "1 of 9. Null Pointer Deref / calloc return value not checked."
Affected Software
3 affected components
Ytnef Project Ytnef<=1.9
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ytnefto a version that resolves this vulnerability.Fixed in 1.9.1
Event History
Feb 24, 2017
CVE Published
via MITRE·04:23 AM
Data Sourced
via MITRE·04:23 AM
Description
Data Sourced
via NVD·04:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6298?
CVE-2017-6298 has a medium severity rating due to potential denial-of-service risks.
2
How do I fix CVE-2017-6298?
To fix CVE-2017-6298, update ytnef to version 1.9.1 or later.
3
Which versions of ytnef are affected by CVE-2017-6298?
CVE-2017-6298 affects ytnef versions prior to 1.9.1.
4
Does CVE-2017-6298 affect Debian Linux?
Yes, CVE-2017-6298 affects Debian Linux versions 8.0 and 9.0.
5
What kind of vulnerability is CVE-2017-6298?
CVE-2017-6298 is a vulnerability related to a null pointer dereference.