Impact
This vulnerability arises from a heap-based buffer overflow in the find_free_number() routine when tnef generates numbered backup suffixes for duplicate filenames. An attacker can craft a TNEF file containing an excessive number of attachments with colliding filenames. When numbered backups are enabled and file overwriting is disabled, the numeric counter is allowed to grow beyond the size of the allocated buffer, which can corrupt memory. The resulting memory corruption may cause the application to crash, producing a denial of service, or, in the worst case, allow an attacker to execute arbitrary code in the context of the running process.
Affected Systems
The affected product is the open-source tnef utility, commonly used as a command‑line tool for extracting attachments from Microsoft Outlook Transport Neutral Encapsulation Format files. No specific version range is listed, so any build of tnef that is vulnerable to the heap overflow should be considered at risk. The vulnerability is likely present in all versions that include the find_free_number() implementation without the additional bounds checks introduced in later fixes.
Risk and Exploitability
The CVSS score for this issue is 3.1, indicating a low overall severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not actively exploited yet. The attack requires an attacker to supply a malicious TNEF file and have the target system run tnef with numbered backups enabled and overwriting disabled. Because the flaw is only triggered when specific conditions are satisfied, the practical likelihood of exploitation is low, but the impact can be significant if an attacker is able to trigger it in a critical environment.
OpenCVE Enrichment