Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An issue has been found in tnef, a tool to unpack MIME application/ms-tnef attachments. Using emails with a crafted winmail.dat application/ms-tnef attachment . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2748-1
TNEF could be made to crash or write arbitrary files to the filesystem.. =========================================================================Ubuntu Security Notice USN-4524-1 September 21, 2020 tnef vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: TNEF could be made to crash or write arbitrary files to the filesystem. Software Description: - tnef: Tool to unpack MIME application/ms-tnef attachments Details: Paul Dreik discovered that TNEF incorrectly handled filenames. If a user were tricked into opening a specially crafted email attachment, an attacker could possibly use this issue to write arbitrary files to the filesystem or cause TNEF crash, resulting in a denial of service. (CVE-2019-18849) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: tnef 1.4.9-1+deb8u4build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4524-1 CVE-2019-18849 Package Information: https://launchpad.net/ubuntu/+source/tnef/1.4.9-1+deb8u4build0.16.04.1 . The recently discovered TNEF weakness permits system crashes or unauthorized file modifications on Ubuntu 16.04 LTS. Ensure you update immediately to protect your system!. tnef vulnerabilities, Ubuntu release, file writing exploit, denial of service issue. . Severity: Critical. LinuxSecurity.com Team
Updated tnef package fixes security vulnerability: In tnef, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based . MGASA-2019-0367 - Updated tnef packages fix security vulnerability Publication date: 06 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0367.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-18849 Updated tnef package fixes security vulnerability: In tnef, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup (CVE-2019-18849). References: - https://bugs.mageia.org/show_bug.cgi?id=25785 - https://lists.debian.org/debian-lts-announce/2019/11/msg00035.html - https://www.cve.org/CVERecord?id=CVE-2019-18849 SRPMS: - 7/core/tnef-1.4.18-1.mga7 . The revised tnef software addresses a vulnerability that permitted unauthorized entry through specially designed email files.. Mageia Security Update, tnef Package Update, Email Exploit. . LinuxSecurity.com Team
tnef release 1.4.18. [CVE-2019-18849](https://www.cve.org/CVERecord?id=CVE-2019-18849) in which it may be possible to attack via a crafted email message extracted via tnef.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-815807c020 2019-12-05 01:39:12.689184 --------------------------------------------------------------------------------Name : tnef Product : Fedora 31 Version : 1.4.18 Release : 1.fc31 URL : https://github.com/verdammelt/tnef Summary : Extract files from email attachments like WINMAIL.DAT Description : This application provides a way to unpack Microsoft MS-TNEF MIME attachments. It operates like tar in order to unpack files of type "application/ms-tnef", which may have been placed into the MS-TNEF attachment instead of being attached separately. Such files may have attachment names similar to WINMAIL.DAT --------------------------------------------------------------------------------Update Information: tnef release 1.4.18. ==================== Security release to resolve [CVE-2019-18849](https://www.cve.org/CVERecord?id=CVE-2019-18849) in which it may be possible to attack via a crafted email message extracted via tnef. --------------------------------------------------------------------------------ChangeLog: * Tue Nov 26 2019 David Timms - 1.4.18-1 - Update to release 1.4.18. Fixes CVE-2019-18849 - bug #1771891 - Add global builddolphin to enable -dolphin subpackage when available. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-815807c020' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
tnef release 1.4.18. [CVE-2019-18849](https://www.cve.org/CVERecord?id=CVE-2019-18849) in which it may be possible to attack via a crafted email message extracted via tnef.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-5f14b810f8 2019-12-05 01:09:44.880069 --------------------------------------------------------------------------------Name : tnef Product : Fedora 30 Version : 1.4.18 Release : 1.fc30 URL : https://github.com/verdammelt/tnef Summary : Extract files from email attachments like WINMAIL.DAT Description : This application provides a way to unpack Microsoft MS-TNEF MIME attachments. It operates like tar in order to unpack files of type "application/ms-tnef", which may have been placed into the MS-TNEF attachment instead of being attached separately. Such files may have attachment names similar to WINMAIL.DAT --------------------------------------------------------------------------------Update Information: tnef release 1.4.18. ==================== Security release to resolve [CVE-2019-18849](https://www.cve.org/CVERecord?id=CVE-2019-18849) in which it may be possible to attack via a crafted email message extracted via tnef. --------------------------------------------------------------------------------ChangeLog: * Tue Nov 26 2019 David Timms - 1.4.18-1 - Update to release 1.4.18. Fixes CVE-2019-18849 - bug #1771891 - Add global builddolphin to enable -dolphin subpackage when available. * Sat Jul 27 2019 Fedora Release Engineering - 1.4.17-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1771892 - CVE-2019-18849 tnef: security bypass in .ssh/authorized_keys file via an e-mail message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1771892 [ 2 ] Bug #1771893 - CVE-2019-18849 tnef: security bypass in.ssh/authorized_keys file via an e-mail message [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1771893 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-5f14b810f8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
In tnef, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based . Package : tnef Version : 1.4.9-1+deb8u4 CVE ID : CVE-2019-18849 Debian Bug : 944851 In tnef, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup. For Debian 8 "Jessie", this problem has been fixed in version 1.4.9-1+deb8u4. We recommend that you upgrade your tnef packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
Update to 1.4.15. Fixes CVE-2017-8911. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-c2882ae75b 2017-10-25 21:34:15.278209 --------------------------------------------------------------------------------Name : tnef Product : Fedora 26 Version : 1.4.15 Release : 1.fc26 URL : https://github.com/verdammelt/tnef Summary : Extract files from email attachments like WINMAIL.DAT Description : This application provides a way to unpack Microsoft MS-TNEF MIME attachments. It operates like tar in order to unpack files of type "application/ms-tnef", which may have been placed into the MS-TNEF attachment instead of being attached separately. Such files may have attachment names similar to WINMAIL.DAT --------------------------------------------------------------------------------Update Information: Update to 1.4.15. Fixes CVE-2017-8911 --------------------------------------------------------------------------------References: [ 1 ] Bug #1427435 - CVE-2017-6307 CVE-2017-6308 CVE-2017-6309 CVE-2017-6310 tnef: Multiple vulnerabilities fixed in 1.4.13 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1427435 [ 2 ] Bug #1451259 - CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451259 [ 3 ] Bug #1451258 - CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451258 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tnef' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to 1.4.15. Fixes CVE-2017-8911. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-2b28a055f2 2017-10-25 19:26:45.871846 --------------------------------------------------------------------------------Name : tnef Product : Fedora 25 Version : 1.4.15 Release : 1.fc25 URL : https://github.com/verdammelt/tnef Summary : Extract files from email attachments like WINMAIL.DAT Description : This application provides a way to unpack Microsoft MS-TNEF MIME attachments. It operates like tar in order to unpack files of type "application/ms-tnef", which may have been placed into the MS-TNEF attachment instead of being attached separately. Such files may have attachment names similar to WINMAIL.DAT --------------------------------------------------------------------------------Update Information: Update to 1.4.15. Fixes CVE-2017-8911 --------------------------------------------------------------------------------References: [ 1 ] Bug #1427435 - CVE-2017-6307 CVE-2017-6308 CVE-2017-6309 CVE-2017-6310 tnef: Multiple vulnerabilities fixed in 1.4.13 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1427435 [ 2 ] Bug #1451259 - CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451259 [ 3 ] Bug #1451258 - CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451258 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tnef' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.