An issue was discovered in ytnef before 1.9.1. This is related to a patch described as “5 of 9. Integer Overflow.”
Monthly Archives: February 2017
CVE-2017-6301 (ytnef)
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as “4 of 9. Out of Bounds Reads.”
CVE-2017-6303 (ytnef)
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as “6 of 9. Invalid Write and Integer Overflow.”
CVE-2017-6197
The r_read_* functions in libr/include/r_endian.h in radare2 1.2.1 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by the r_read_le32 function.
CVE-2017-6298 (ytnef)
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as “1 of 9. Null Pointer Deref / calloc return value not checked.”
CVE-2017-6305 (ytnef)
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as “8 of 9. Out of Bounds read and write.”
CVE-2017-6304 (ytnef)
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as “7 of 9. Out of Bounds read.”
CVE-2017-6307 (tnef)
An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, controlled by an attacker.
CVE-2017-6310 (tnef)
An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.
CVE-2017-6309 (tnef)
An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.