In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2021-03-04T21:10:57

Updated: 2024-08-03T16:53:17.530Z

Reserved: 2021-02-09T00:00:00

Link: CVE-2021-3404

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-04T22:15:14.657

Modified: 2024-11-21T06:21:25.553

Link: CVE-2021-3404

cve-icon Redhat

No data.