Impact
The bug resides in tnef's get_rtf_data_from_buf function. When an attacker supplies a specially crafted RTF payload, the function reads past the allocated buffer. This out‑of‑bounds read can cause the program to crash, triggering a denial of service, or expose sensitive memory content in the output file.
Affected Systems
The affected component is the tnef utility used to extract or consume Microsoft Exchange MPF attachments. No specific version range is listed in the advisory, so all releases that still include the vulnerable code are potentially impacted. Systems that use tnef as part of email processing or archival should confirm their installed version.
Risk and Exploitability
The CVSS score of 5.4 points to moderate severity. The EPSS score is currently unavailable, and the vulnerability is not listed in CISA's KEV catalog. An attacker must provide a malicious RTF file that the vulnerable process consumes; if the application runs as a privileged user, the memory leak could reveal confidential data. Because the flaw is an out‑of‑bounds read, the impact is limited to denial of service or data leakage and does not allow arbitrary code execution.
OpenCVE Enrichment