Mageia 2022-0316: ytnef security update
Summary
In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows
remote attackers to cause a denial-of-service (and potentially code
execution) due to a double free which can be triggered via a crafted file.
(CVE-2021-3403)
In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote
attackers to cause a denial-of-service (and potentially code execution)
due to a heap buffer overflow which can be triggered via a crafted file.
(CVE-2021-3404)
References
- https://bugs.mageia.org/show_bug.cgi?id=30735
- https://github.com/Yeraze/ytnef/releases
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3403
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3404
Resolution
MGASA-2022-0316 - Updated ytnef packages fix security vulnerability
SRPMS
- 8/core/ytnef-2.0-1.mga8