Updated libytnef packages fix security vulnerabilities
Publication date: 14 Jun 2017Modification date: 14 Jun 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2017-6298 , CVE-2017-6299 , CVE-2017-6300 , CVE-2017-6301 , CVE-2017-6302 , CVE-2017-6303 , CVE-2017-6304 , CVE-2017-6305 , CVE-2017-6306 , CVE-2017-6800 , CVE-2017-6801 , CVE-2017-6802 , CVE-2017-9058
Description
Several issues were discovered in libytnef, a library used to decode application/ms-tnef e-mail attachments. Multiple heap overflows, out-of-bound writes and reads, NULL pointer dereferences and infinite loops could be exploited by tricking a user into opening a maliciously crafted winmail.dat file (CVE-2017-6298, CVE-2017-6299, CVE-2017-6300, CVE-2017-6301, CVE-2017-6302, CVE-2017-6303, CVE-2017-6304, CVE-2017-6305, CVE-2017-6306, CVE-2017-6800, CVE-2017-6801, CVE-2017-6802). A heap-buffer-overflow vulnerability in libytnef due to an incorrect boundary checking in SIZECHCK macro in lib/ytnef.c (CVE-2017-9058).
References
- https://bugs.mageia.org/show_bug.cgi?id=20893
- http://openwall.com/lists/oss-security/2017/02/15/4
- https://www.debian.org/security/2017/dsa-3846
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862556
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6298
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6299
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6300
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6301
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6302
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6303
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6304
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6305
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6306
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6800
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6801
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6802
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9058
SRPMS
5/core
- libytnef-1.5-10.2.mga5