CVE-2009-3721
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.61% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- gnome/evolution · ytnef project/ytnef
- Source
- secalert@redhat.com
References
- http://www.ocert.org/advisories/ocert-2009-013.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=521662Issue Tracking, Patch, Third Party Advisory
- http://www.ocert.org/advisories/ocert-2009-013.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=521662Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.