stable

tnef-1.4.15-1.fc26

FEDORA-2017-c2882ae75b created by kevin 7 years ago for Fedora 26

Update to 1.4.15. Fixes CVE-2017-8911

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2017-c2882ae75b

This update has been submitted for testing by kevin.

7 years ago

This update has been pushed to testing.

7 years ago

This update has reached 7 days in testing and can be pushed to stable now if the maintainer wishes

7 years ago
User Icon hreindl commented & provided feedback 7 years ago
karma

works for me

This update has been submitted for batched by kevin.

7 years ago

This update has been submitted for stable by bodhi.

7 years ago
User Icon dtimms commented & provided feedback 7 years ago

tnef 1.4.15 fc26 runs, but: testing with the proof of concept generates an assert and core dump. I'm not sure that it should core dump..I would have expected an error message / errorlevel return.

I've asked at: https://github.com/verdammelt/tnef/issues/23

p.s. thanks to Kevin for noticing / updating my package.

User Icon genodeftest commented & provided feedback 7 years ago
karma

Extracting a TNEF attachment works fine for me.

This update has been pushed to stable.

7 years ago
User Icon dtimms commented & provided feedback 7 years ago
karma

Extracting conforming content works OK. Extracting from the faulty ProofOfConcept tnef file generates an assertion and core dump. The program author says the core dump is expected.

BZ#1451258 CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [fedora-all]

Please log in to add feedback.

Metadata
Type
security
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
disabled
Dates
submitted
7 years ago
in testing
7 years ago
in stable
7 years ago
BZ#1427435 CVE-2017-6307 CVE-2017-6308 CVE-2017-6309 CVE-2017-6310 tnef: Multiple vulnerabilities fixed in 1.4.13 [epel-all]
0
0
BZ#1451258 CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [fedora-all]
0
1
BZ#1451259 CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [epel-all]
0
0

Automated Test Results