CVE-2017-9474: Medium severity Ytnef Project Ytnef vulnerability
Published Jun 7, 2017
·Updated
In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
Affected Software
1 affected component
Ytnef Project Ytnef=1.9.2
Event History
Jun 7, 2017
CVE Published
via MITRE·04:50 AM
Data Sourced
via MITRE·04:50 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9474?
CVE-2017-9474 has been classified as a denial of service vulnerability that can lead to an application crash.
2
How do I fix CVE-2017-9474?
To mitigate CVE-2017-9474, it is recommended to upgrade to a version of ytnef that is not affected by this vulnerability.
3
What products are affected by CVE-2017-9474?
CVE-2017-9474 specifically affects ytnef version 1.9.2.
4
What type of attack is associated with CVE-2017-9474?
CVE-2017-9474 allows remote attackers to execute a denial of service attack via a crafted file.
5
Can CVE-2017-9474 be exploited remotely?
Yes, CVE-2017-9474 can be exploited by remote attackers to cause a denial of service.