See how tnef project compares to other vendors in security performance
An integer underflow has been identified in the unicodetoutf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker.
An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parsefile() function. These might lead to invalid read and write operations, controlled by an attacker.
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the fileaddmapiattrs() function. These might lead to invalid read and write operations, controlled by an attacker.
An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapiattr.c:mapiattrread(). These might lead to invalid read and write operations, controlled by an attacker.
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorizedkeys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.