Vulnerability Bulletins

DSA-3798 tnef - security update

   
Affected software Debian
 
Eric Sesterhenn, from X41 D-Sec GmbH, discovered severalvulnerabilities in tnef, a tool used to unpack MIME attachments oftype application/ms-tnef. Multiple heap overflows, type confusionsand out of bound reads and writes could be exploited by tricking auser into opening a malicious attachment. This would result in denialof service via application crash, or potential arbitrary codeexecution.

More info:

https://www.debian.org/security/2017/dsa-3798