Unrated severityNVD Advisory· Published May 5, 2014· Updated May 6, 2026
CVE-2010-5109
CVE-2010-5109
Description
Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remote attackers to cause a denial of service (crash) via a crafted TNEF file, which triggers a buffer overflow.
Affected products
3- cpe:2.3:a:randall_hand:yerase\'s_tnef_stream_reader:-:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- sourceforge.net/p/ytnef/bugs/13/nvd
- www.openwall.com/lists/oss-security/2013/04/11/1nvd
- www.securityfocus.com/bid/54484nvd
- bugzilla.redhat.com/show_bug.cginvd
- lists.fedoraproject.org/pipermail/package-announce/2012-July/083804.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2012-July/083853.htmlnvd
News mentions
0No linked articles in our index yet.