CVE-2017-6300: Buffer Overflow
Published Feb 24, 2017
·Updated
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "3 of 9. Buffer Overflow in version field in lib/tnef-types.h."
Affected Software
3 affected components
Ytnef Project Ytnef<=1.9
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ytnefto a version that resolves this vulnerability.Fixed in 1.9.1
Event History
Feb 24, 2017
CVE Published
via MITRE·04:23 AM
Data Sourced
via MITRE·04:23 AM
Description
Data Sourced
via NVD·04:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6300?
CVE-2017-6300 is classified as a medium severity vulnerability due to the potential for a buffer overflow.
2
How do I fix CVE-2017-6300?
To fix CVE-2017-6300, update ytnef to version 1.9.1 or later.
3
What systems are affected by CVE-2017-6300?
CVE-2017-6300 affects ytnef versions prior to 1.9.1 and Debian versions 8.0 and 9.0.
4
What type of vulnerability is CVE-2017-6300?
CVE-2017-6300 is a buffer overflow vulnerability that occurs in the version field of ytnef.
5
Is there a known exploitation of CVE-2017-6300?
As of now, there are no reports of active exploitation in the wild for CVE-2017-6300.