#VU38889 Out-of-bounds read in ytnef - CVE-2017-9474
Published: June 7, 2017 / Updated: September 20, 2021
ytnef
Yeraze (Randall Hand)
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c. A remote attacker can perform a denial of service (heap-based buffer over-read and application crash) via a crafted file.