Integer overflow in Debian Linux - CVE-2017-6308

 

Integer overflow in Debian Linux - CVE-2017-6308

Published: February 24, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39636
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6308
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.


Affected software

Debian Linux
Gentoo Linux
Fedora
tnef

How to mitigate CVE-2017-6308

Install update from vendor's website.

tnef - addressed in versions 1.4.14-1.el6, 1.4.14-1.el7, 1.4.14-2.fc24, 1.4.14-2.fc25, 1.4.14-2.fc26, 1.4.15-1.el6, 1.4.15-1.el7, 1.4.15-1.fc25, 1.4.15-1.fc26, 1.4.15-1.fc27

External References

Related Security Bulletins