CVE-2017-6308: Integer Overflow
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
The CVSS vector indicates local attack access and user interaction are required. No privileges are required, but exploitation depends on a user interacting with malicious input.
The issue affects tnef versions before 1.4.13. The listed affected software includes Tnef Project Tnef and Debian Debian Linux.
The identified integer overflows can lead to heap overflows in memory-allocation wrapper functions. The CVSS vector rates confidentiality, integrity, and availability impact as high.
Apply the available patch and upgrade tnef to a version that is not before 1.4.13. The provided Debian security advisory may contain distribution-specific remediation information.