REDHAT-BUG-2544478: Low severity tnef vulnerability
A flaw was found in tnef. findfreenumber() allocates a fixed-size buffer sized for a 5-digit numeric backup suffix, but formats the counter with an unbounded sprintf(). When the --number-backups option is enabled and overwrite is disabled, a crafted TNEF stream that forces roughly 100,000 colliding candidate filenames for a single extracted attachment causes the counter to require six digits, writing past the end of the allocated heap buffer. The issue requires a non-default command-line option and a large, specially crafted input to trigger.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Only tnef invocations that enable the non-default --number-backups option while overwrite is disabled are exposed. Default command-line usage is not affected by the described condition.
What must an attacker provide to trigger the overflow?
An attacker needs a specially crafted TNEF stream that causes about 100,000 candidate filename collisions for one extracted attachment. This forces the backup counter beyond five digits and writes past the fixed-size heap buffer.
What can be done if the affected option cannot be avoided?
Avoid processing untrusted TNEF streams with --number-backups enabled and overwrite disabled. The trigger depends on producing a very large number of filename collisions for a single attachment.