CVE-2017-9058: Critical severity Ytnef Project Ytnef vulnerability
In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9058?
CVE-2017-9058 is classified as a moderate severity vulnerability due to its heap-based buffer over-read which can lead to information disclosure.
How do I fix CVE-2017-9058?
To fix CVE-2017-9058, upgrade libytnef to version 1.9.3-1, 1.9.3-3, 2.0-1, or 2.1.2-1 on Debian systems, or to 1.5-6ubuntu0.2 on Ubuntu systems.
What are the affected versions related to CVE-2017-9058?
CVE-2017-9058 affects versions of libytnef from 1.9.2 and earlier.
Is my system vulnerable to CVE-2017-9058?
If you are using any version of libytnef prior to 1.9.3-1 on Debian or prior to 1.5-6ubuntu0.2 on Ubuntu, your system is vulnerable to CVE-2017-9058.
What impact does CVE-2017-9058 have on an affected system?
CVE-2017-9058 can lead to heap-based buffer over-read which may potentially allow an attacker to read sensitive information from memory.