REDHAT-BUG-2544476: Medium severity tnef vulnerability
A flaw was found in tnef. The TNEF uncompressed-RTF value handler in getrtfdatafrombuf() copies an attacker-controlled uncomprsize number of bytes from the input buffer without validating that the buffer actually contains that much data beyond the 16-byte value header, resulting in a heap out-of-bounds read. The issue was confirmed under AddressSanitizer and can crash the process; when body extraction (--save-body) is enabled, the over-read memory is written into the extracted RTF output file.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to provide to trigger this issue?
An attacker needs to supply a TNEF input containing an uncompressed RTF value whose attacker-controlled uncompr_size exceeds the data available after the 16-byte value header.
What is the practical impact when processing a malicious file?
The flaw causes a heap out-of-bounds read and can crash the tnef process. If body extraction is enabled with --save-body, memory read beyond the input buffer is written to the extracted RTF output file.
How can I determine whether extracted output may be affected?
Check whether tnef was run with the --save-body option on untrusted TNEF files. In that configuration, a malformed uncompressed RTF value can cause over-read memory to be included in the generated RTF file.