CVE-2021-3404
Summary
| CVE | CVE-2021-3404 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-04 22:15:00 UTC |
| Updated | 2022-04-25 20:25:00 UTC |
| Description | In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1926965 – (CVE-2021-3404) CVE-2021-3404 ytnef: heap-based buffer overflow in SwapWord function in lib/ytnef.c via crafted file |
MISC |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Heap buffer overflow via TNEFVersion · Issue #86 · Yeraze/ytnef · GitHub |
MISC |
github.com |
Exploit, Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180246 Debian Security Update for libytnef (CVE-2021-3404)
- 501725 Alpine Linux Security Update for ytnef