You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa tnef

Sigurnosni nedostatak programskog paketa tnef

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4524-1
September 21, 2020

tnef vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.04 LTS

Summary:

TNEF could be made to crash or write arbitrary files to the filesystem.

Software Description:
– tnef: Tool to unpack MIME application/ms-tnef attachments

Details:

Paul Dreik discovered that TNEF incorrectly handled filenames. If a user
were tricked into opening a specially crafted email attachment, an
attacker could possibly use this issue to write arbitrary files to the
filesystem or cause TNEF crash, resulting in a denial of service.
(CVE-2019-18849)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
tnef 1.4.9-1+deb8u4build0.16.04.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4524-1
CVE-2019-18849

Package Information:
https://launchpad.net/ubuntu/+source/tnef/1.4.9-1+deb8u4build0.16.04.1

—–BEGIN PGP SIGNATURE—–

iQEzBAEBCAAdFiEElnO/d49FoUPK9fwytGdj0GOh2+wFAl9pNBIACgkQtGdj0GOh
2+x/agf+KNk5Yo/5OfEOepqVKBnIWU09tz4tmIOzT7DQ55y9lJHTihcIoMnhVlaj
D3mgyna8RIAvcjiLipyDO4vPW+BI+1P+bHUntQ4qYNSFqOZzULFJ2i673L3cNdb4
R9+i0JE9PqwnnwACpOsV2ZgypXrf1meKO80UhgWrFWjbpjIX1XJwUD5J1SYKbt7G
rs8zPfdsfJJcsxHBiOGY8/Smn8/p4LWXugR5J8IUbiKqR91hzNyJ/e+ONnL0dbj7
MZSqt810nwCa10x/LKvHUi3mtSi//9+DQcpwD8tmaDGh2BmAkBNniqa4CzvKdd9M
AG00p+EiXYNHFoAtHuVbtcjOCHseUQ==
=xGCI
—–END PGP SIGNATURE—–

AutorBruno Varga
Cert idNCERT-REF-2020-09-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programske biblioteke libofx

Otkriven je sigurnosni nedostatak programske biblioteke libofx za operacijski sustav Ubuntu. Otkriveni nedostatak potencijalnim napadačima omogućuje izazivanje DoS stanja. Savjetuje...

Close