Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in tnef. The TNEF uncompressed-RTF value handler in get_rtf_data_from_buf() copies an attacker-controlled uncompr_size number of bytes from the input buffer without validating that the buffer actually contains that much data beyond the 16-byte value header, resulting in a heap out-of-bounds read. The issue was confirmed under AddressSanitizer and can crash the process; when body extraction (--save-body) is enabled, the over-read memory is written into the extracted RTF output file.