Oval Definition:oval:org.cisecurity:def:1934
Revision Date:2017-03-10Version:2
Title:DSA-3798-1 -- tnef -- security update
Description:Eric Sesterhenn, from X41 D-Sec GmbH, discovered several vulnerabilities in tnef, a tool used to unpack MIME attachments of type 'application/ms-tnef'. Multiple heap overflows, type confusions and out of bound reads and writes could be exploited by tricking a user into opening a malicious attachment. This would result in denial of service via application crash, or potential arbitrary code execution.
Family:unixClass:patch
Status:DRAFTReference(s):CVE-2017-6307
CVE-2017-6308
CVE-2017-6309
CVE-2017-6310
DSA-3798-1
Platform(s):Debian 8
Product(s):tnef
Definition Synopsis
  • Debian 8 is installed
  • AND tnef is earlier than 0:1.4.9-1+deb8u1
  • BACK