Description
Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remote attackers to cause a denial of service (crash) via a crafted TNEF file, which triggers a buffer overflow.
References (6)
Core 6
Core References
Product x_refsource_misc
http://sourceforge.net/p/ytnef/bugs/13/
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=831322
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/04/11/1
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/54484
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/pipermail/package-announce/2012-July/083804.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/pipermail/package-announce/2012-July/083853.html
Scores
EPSS
0.0239
EPSS Percentile
82.2%
Details
CWE
CWE-189
Status
published
Products (3)
fedoraproject/fedora
16
fedoraproject/fedora
17
randall_hand/yerase\'s_tnef_stream_reader
Published
May 05, 2014
Tracked Since
Feb 18, 2026