In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2021-03-04T21:10:57

Updated: 2024-08-03T16:53:17.530Z

Reserved: 2021-02-09T00:00:00

Link: CVE-2021-3404

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-03-04T22:15:14.657

Modified: 2022-04-25T20:25:57.287

Link: CVE-2021-3404

cve-icon Redhat

No data.