CVE-2017-6801: High severity Ytnef Project Ytnef vulnerability
Published Mar 10, 2017
·Updated
An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.
Affected Software
3 affected components
Ytnef Project Ytnef<=1.9.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Event History
Mar 10, 2017
CVE Published
via MITRE·10:29 AM
Data Sourced
via MITRE·10:29 AM
Description
Data Sourced
via NVD·10:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6801?
CVE-2017-6801 has a high severity rating due to potential out-of-bounds access vulnerabilities.
2
How do I fix CVE-2017-6801?
To fix CVE-2017-6801, update ytnef to version 1.9.2 or later.
3
Which software versions are affected by CVE-2017-6801?
CVE-2017-6801 affects ytnef versions before 1.9.2 and Debian Linux versions 8.0 and 9.0.
4
What impact does CVE-2017-6801 have on my system?
CVE-2017-6801 may allow attackers to exploit out-of-bounds access, leading to potential arbitrary code execution.
5
Is there a workaround for CVE-2017-6801 if I cannot update?
There is no known workaround for CVE-2017-6801, so upgrading to a non-vulnerable version is recommended.