Description
A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is disabled, an attacker can supply a specially crafted Transport Neutral Encapsulation Format (TNEF) file with an excessive number of colliding attachment filenames, causing the numeric counter to write past the allocated memory buffer. This issue may result in an application crash, leading to a Denial of Service (DoS), or potentially arbitrary code execution.
Published: 2026-10-01
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: Potential Denial of Service due to heap buffer overflow
Action: Assess
AI Analysis

Impact

This vulnerability arises from a heap-based buffer overflow in the find_free_number() routine when tnef generates numbered backup suffixes for duplicate filenames. An attacker can craft a TNEF file containing an excessive number of attachments with colliding filenames. When numbered backups are enabled and file overwriting is disabled, the numeric counter is allowed to grow beyond the size of the allocated buffer, which can corrupt memory. The resulting memory corruption may cause the application to crash, producing a denial of service, or, in the worst case, allow an attacker to execute arbitrary code in the context of the running process.

Affected Systems

The affected product is the open-source tnef utility, commonly used as a command‑line tool for extracting attachments from Microsoft Outlook Transport Neutral Encapsulation Format files. No specific version range is listed, so any build of tnef that is vulnerable to the heap overflow should be considered at risk. The vulnerability is likely present in all versions that include the find_free_number() implementation without the additional bounds checks introduced in later fixes.

Risk and Exploitability

The CVSS score for this issue is 3.1, indicating a low overall severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not actively exploited yet. The attack requires an attacker to supply a malicious TNEF file and have the target system run tnef with numbered backups enabled and overwriting disabled. Because the flaw is only triggered when specific conditions are satisfied, the practical likelihood of exploitation is low, but the impact can be significant if an attacker is able to trigger it in a critical environment.

Generated by OpenCVE AI on October 1, 2026 at 12:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable the numbered backup feature or file overwriting in the tnef configuration to avoid invoking the vulnerable routine
  • Upgrade tnef to the latest release that contains the patch for the heap overflow
  • If an update is not immediately available, restrict the use of tnef to non‑trusted files or temporarily block the program until a fix is applied

Generated by OpenCVE AI on October 1, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is disabled, an attacker can supply a specially crafted Transport Neutral Encapsulation Format (TNEF) file with an excessive number of colliding attachment filenames, causing the numeric counter to write past the allocated memory buffer. This issue may result in an application crash, leading to a Denial of Service (DoS), or potentially arbitrary code execution.
Title Tnef: heap buffer overflow in find_free_number() via numbered-backup suffix generation
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-10-01T11:34:51.984Z

Reserved: 2026-10-01T09:06:43.923Z

Link: CVE-2026-103680

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T12:17:15.810

Modified: 2026-10-01T12:17:15.810

Link: CVE-2026-103680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T12:30:07Z

Weaknesses