• [SECURITY] [DSA 3869-1] tnef security update

    From Sebastien Delafond@1:229/2 to All on Thu Jun 1 07:10:02 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3869-1 [email protected] https://www.debian.org/security/ Sebastien Delafond
    June 01, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : tnef
    CVE ID : CVE-2017-8911
    Debian Bug : 862442

    It was discovered that tnef, a tool used to unpack MIME attachments of
    type "application/ms-tnef", did not correctly validate its input. An
    attacker could exploit this by tricking a user into opening a
    malicious attachment, which would result in a denial-of-service by
    application crash.

    For the stable distribution (jessie), this problem has been fixed in
    version 1.4.9-1+deb8u3.

    For the unstable distribution (sid), this problem has been fixed in
    version 1.4.12-1.2.

    We recommend that you upgrade your tnef packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlkvnukACgkQEL6Jg/PV nWRrlwf+NTs5cdVBCgRRSiWLGSxxXDO48LSpTgd0ir8gQZ7YD5kDfG3dE20gjVnK I11PqtymS2YIg93l7yjwPH9QZjBi5bgMRUz65axDgQWB46bMITAo93uU/Wqa9JDw FNE4u83Iuw8S/QeJj7HG0fQkSCRD/zJSz82D//IURQJ8idXbZ1Iv0Mo8er/To55i kE0TEqD6Dya88ikF7GK38OsQbFzTH+4NhqFKMzs5COq5kkJUiQXU4hnjRGvhHshR BOuhM201GX2cbG/bWOg6mTzbrvjpyEZXB8J9i2f0lKo0Nx8lvl+teOvfKpNm0zrO ER9mGbGkIo+AJblsKRWQZF0AnTGDdA==
    =yM/l
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)