Vulnerability Description
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tnef Project | Tnef | <= 1.4.12 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.debian.org/security/2017/dsa-3798Third Party Advisory
- http://www.securityfocus.com/bid/96427Third Party AdvisoryVDB Entry
- https://github.com/verdammelt/tnef/blob/master/ChangeLogPatchRelease NotesThird Party Advisory
- https://github.com/verdammelt/tnef/commit/c5044689e50039635e7700fe2472fd632ac771Issue TrackingPatchThird Party Advisory
- https://security.gentoo.org/glsa/201708-02Third Party Advisory
- https://www.x41-dsec.de/lab/advisories/x41-2017-004-tnef/PatchThird Party Advisory
- http://www.debian.org/security/2017/dsa-3798Third Party Advisory
- http://www.securityfocus.com/bid/96427Third Party AdvisoryVDB Entry
- https://github.com/verdammelt/tnef/blob/master/ChangeLogPatchRelease NotesThird Party Advisory
- https://github.com/verdammelt/tnef/commit/c5044689e50039635e7700fe2472fd632ac771Issue TrackingPatchThird Party Advisory
- https://security.gentoo.org/glsa/201708-02Third Party Advisory
- https://www.x41-dsec.de/lab/advisories/x41-2017-004-tnef/PatchThird Party Advisory
FAQ
What is CVE-2017-6308?
CVE-2017-6308 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
How severe is CVE-2017-6308?
CVE-2017-6308 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6308?
Check the references section above for vendor advisories and patch information. Affected products include: Tnef Project Tnef, Debian Debian Linux.