CVE-2017-6299: Medium severity Ytnef Project Ytnef vulnerability
Published Feb 24, 2017
·Updated
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infinite Loop / DoS in the TNEFFillMapi function in lib/ytnef.c."
Affected Software
3 affected components
Ytnef Project Ytnef<=1.9
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Feb 24, 2017
CVE Published
via MITRE·04:23 AM
Data Sourced
via MITRE·04:23 AM
Description
Data Sourced
via NVD·04:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6299?
CVE-2017-6299 has a moderate severity due to its potential for causing a Denial of Service through an infinite loop.
2
How do I fix CVE-2017-6299?
To fix CVE-2017-6299, update ytnef to version 1.9.1 or later.
3
What software is affected by CVE-2017-6299?
CVE-2017-6299 affects ytnef versions prior to 1.9.1, as well as Debian Linux 8.0 and 9.0.
4
What type of vulnerability is CVE-2017-6299?
CVE-2017-6299 is a Denial of Service (DoS) vulnerability that could lead to an infinite loop in the software.
5
Is there a patch available for CVE-2017-6299?
Yes, a patch is available in version 1.9.1 of ytnef which addresses CVE-2017-6299.