Several security issues were fixed in libytnef.. =========================================================================Ubuntu Security Notice USN-3667-1 May 31, 2018 libytnef vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in libytnef. Software Description: - libytnef: improved decoder for application/ms-tnef attachments Details: It was discovered that libytnef incorrectly handled certain files. An attacker could possibly use this to cause a denial of service. (CVE-2017-12141, CVE-2017-9146, CVE-2017-9471, CVE-2017-9473) It was discovered that libytnef incorrectly handled certain files. An attacker could possibly use this to access sensitive information. (CVE-2017-9058) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: libytnef0 1.5-6ubuntu0.2 After a standard system update you need to restart applications using libytnef, such as Evolution, to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3667-1 CVE-2017-12141, CVE-2017-9058, CVE-2017-9146, CVE-2017-9471, CVE-2017-9473 Package Information: https://launchpad.net/ubuntu/+source/libytnef/1.5-6ubuntu0.2 . Critical notice regarding libytnef flaws in Ubuntu 14.04, impacting system integrity and necessitating prompt updates.. libytnef vulnerabilities,Ubuntu security update,denial of service. . Severity: Important. LinuxSecurity.com Team
The package libytnef before version 1.9.2-2 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-201708-10 ========================================= Severity: High Date : 2017-08-14 CVE-ID : CVE-2017-9058 Package : libytnef Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-275 Summary ====== The package libytnef before version 1.9.2-2 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 1.9.2-2. # pacman -Syu "libytnef> =1.9.2-2" The problem has been fixed upstream but no release is available yet. Workaround ========= None. Description ========== A heap-buffer-overflow vulnerability has been found in the libytnef in the lib/ytnef.c module. Impact ===== A remote attacker can execute arbitrary code on the affected host via a crafted tnef file. References ========= https://raw.githubusercontent.com/bingosxs/fuzzdata/master/ytnef-1.9/TNEFFreeMapiProps-Invalid-read.tnef https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862556 https://security.archlinux.org/CVE-2017-9058 . Fedora Security Notice FSA-202112-15 Highlights critical vulnerability in libfilehandler, potentially enabling remote code execution.. libytnef Execution, Arch Linux Advisory, High Severity Threat, Code Execution Risk. . LinuxSecurity.com Team
libytnef could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-3288-1 May 15, 2017 libytnef vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: libytnef could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - libytnef: improved decoder for application/ms-tnef attachments Details: It was discovered that libytnef incorrectly handled malformed TNEF streams. If a user were tricked into opening a specially crafted TNEF attachment, an attacker could cause a denial of service or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: libytnef0 1.5-6ubuntu0.1 After a standard system update you need to restart applications using libytnef, such as Evolution, to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3288-1 CVE-2017-6298, CVE-2017-6299, CVE-2017-6300, CVE-2017-6301, CVE-2017-6302, CVE-2017-6303, CVE-2017-6304, CVE-2017-6305, CVE-2017-6306, CVE-2017-6800, CVE-2017-6801, CVE-2017-6802 Package Information: https://launchpad.net/ubuntu/+source/libytnef/1.5-6ubuntu0.1 . Ubuntu Security Notice USN-3290-2 addresses vulnerabilities in libxyz that could potentially result in application failures or arbitrary code execution.. libytnef vulnerabilities, Ubuntu security update, denial of service, crafted file attack. . Severity: Critical. LinuxSecurity.com Team
Several issues were discovered in libytnef, a library used to decode application/ms-tnef e-mail attachments. Multiple heap overflows, out-of-bound writes and reads, NULL pointer dereferences and infinite loops could be exploited by tricking a user into opening a maliciously . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3846-1
Get the latest Linux and open source security news straight to your inbox.