Impact
The flaw lies in the TNEF parsing routine get_body_files(), where improper memory management leads to a use‑after‑free and double‑free when multiple message bodies are extracted. A specially crafted TNEF file allows a remote attacker to trigger this bug, causing the application to crash and resulting in a denial of service. The vulnerability highlights a classic unsafe dereference (CWE‑416).
Affected Systems
This issue affects the tnef utility used to process TNEF files. No vendor or product version details are supplied in the advisory, so any system running an unpatched copy of tnef may be vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity attack. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation is not yet reported. Nonetheless, because the flaw can be triggered by an unauthenticated remote user providing a crafted file, the risk remains for systems that accept TNEF data from untrusted sources.
OpenCVE Enrichment