Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Untriaged
created 2 months ago Activity log
  • Created suggestion
Multiple directory traversal and buffer overflow vulnerabilities were discovered in …

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.

References

Affected products

ytnef
  • ==ytnef 2.8

Matching in nixpkgs

pkgs.libytnef

Yeraze's TNEF Stream Reader - for winmail.dat files

Package maintainers