• [SECURITY] [DSA 3846-1] libytnef security update

    From Sebastien Delafond@1:229/2 to All on Tue May 9 11:40:02 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3846-1 [email protected] https://www.debian.org/security/ Sebastien Delafond
    May 09, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : libytnef
    CVE ID : CVE-2017-6298 CVE-2017-6299 CVE-2017-6300 CVE-2017-6301
    CVE-2017-6302 CVE-2017-6303 CVE-2017-6304 CVE-2017-6305
    CVE-2017-6306 CVE-2017-6800 CVE-2017-6801 CVE-2017-6802
    Debian Bug :

    Several issues were discovered in libytnef, a library used to decode application/ms-tnef e-mail attachments. Multiple heap overflows,
    out-of-bound writes and reads, NULL pointer dereferences and infinite
    loops could be exploited by tricking a user into opening a maliciously
    crafted winmail.dat file.

    For the stable distribution (jessie), these problems have been fixed in
    version 1.5-6+deb8u1.

    For the upcoming stable (stretch) and unstable (sid) distributions,
    these problems have been fixed in version 1.9.2-1.

    We recommend that you upgrade your libytnef packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlkRizwACgkQEL6Jg/PV nWSPBwf9H4Ztk9ZbE/MK/JKkwlett/yMn+LeeO62nge3QjT+JNf2polUZf2wJB1C f5mXtsW4MTtwuVcbc8ex64xnmffyGS06MpkB+G1+lVbYniGpGM8jPzE0zTOMGdos LnVM3fQe2meHbV9Sc4KO9IvFeIQppnwxvviIuPmTGvsqdnPI1j/yqPXlHgxUuxeB QR3+4wuGbB25/lms7sZF+0vOrZYeWEecIGglMZ05gMBtsFFizfAUy2M7K3IU9qkL sgn5o9h5980GwGrRmGznqpOvhPwfZHPg754XyRTi6kxUwPWejjYTg0yLKDDNQJJ5 0hwvZP2gESynf4nUdCZLXVpKVKyVEw==
    =TGgR
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)