CVE-2017-6802: High severity Ytnef Project Ytnef vulnerability
Published Mar 10, 2017
·Updated
An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.
Affected Software
3 affected components
Ytnef Project Ytnef<=1.9.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Mar 10, 2017
CVE Published
via MITRE·10:29 AM
Data Sourced
via MITRE·10:29 AM
Description
Data Sourced
via NVD·10:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6802?
CVE-2017-6802 has a medium severity rating due to the potential for exploitation via heap-based buffer over-reads.
2
How do I fix CVE-2017-6802?
To fix CVE-2017-6802, update ytnef to version 1.9.2 or later.
3
Which versions of ytnef are affected by CVE-2017-6802?
Versions of ytnef prior to 1.9.2, specifically all versions up to and including 1.9.1, are affected by CVE-2017-6802.
4
What types of systems are impacted by CVE-2017-6802?
CVE-2017-6802 impacts systems running ytnef versions before 1.9.2, including Debian Linux versions 8.0 and 9.0.
5
What does CVE-2017-6802 affect in the application?
CVE-2017-6802 affects the handling of incoming Compressed RTF Streams in the DecompressRTF() function.