CVE-2017-9472: Medium severity Ytnef Project Ytnef vulnerability
Published Jun 7, 2017
·Updated
In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Affected Software
1 affected component
Ytnef Project Ytnef=1.9.2
Event History
Jun 7, 2017
CVE Published
via MITRE·04:50 AM
Data Sourced
via MITRE·04:50 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9472?
CVE-2017-9472 has a severity rating that can lead to denial of service through heap-based buffer over-read.
2
How do I fix CVE-2017-9472?
To fix CVE-2017-9472, upgrade ytnef to a version beyond 1.9.2 where the vulnerability is addressed.
3
What type of attack does CVE-2017-9472 enable?
CVE-2017-9472 enables remote attackers to perform denial of service attacks by exploiting a vulnerability in ytnef.
4
What software is affected by CVE-2017-9472?
CVE-2017-9472 specifically affects ytnef version 1.9.2.
5
Can CVE-2017-9472 cause data loss?
CVE-2017-9472 primarily leads to application crashes, which can disrupt service but does not directly cause data loss.