user/catdoc: CVE-2017-11110: ole_init heap-based underflow
Bugzilla ID | 160 |
Alias(es) | CVE-2017-11110 |
Reporter | Max Rees (sroracle) |
Assignee | Max Rees (sroracle) |
Reported | 2019-07-31 10:16:57 -0500 |
Modified | 2019-08-04 19:19:09 -0500 |
Status | RESOLVED FIXED |
Version | 1.0-BETA3 |
Hardware | Adélie Linux / All |
Importance | --- / normal |
URL | https://nvd.nist.gov/vuln/detail/CVE-2017-11110 |
Description
The ole_init function in ole.c in catdoc 0.95 allows remote attackers
to cause a denial of service (heap-based buffer underflow and
application crash) or possibly have unspecified other impact via a
crafted file, i.e., data is written to memory addresses before the
beginning of the tmpBuf buffer.