In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2021-03-04T21:10:50

Updated: 2024-08-03T16:53:17.578Z

Reserved: 2021-02-09T00:00:00

Link: CVE-2021-3403

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-03-04T22:15:14.577

Modified: 2022-04-25T20:17:58.637

Link: CVE-2021-3403

cve-icon Redhat

No data.