{"id":"MGASA-2014-0531","summary":"Updated claws-mail packages fix security vulnerability","details":"Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF\nStream Reader allows remote attackers to cause a denial of service (crash)\nvia a crafted TNEF file, which triggers a buffer overflow (CVE-2010-5109).\n\nThe claws-mail package contains an embedded copf of libytnef, which has been\npatched to fix this issue.\n","modified":"2026-04-16T06:23:19.209655907Z","published":"2014-12-19T15:06:35Z","upstream":["CVE-2010-5109"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0531.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14743"},{"type":"WEB","url":"http://sourceforge.net/tracker/?func=detail&aid=2949686&group_id=70352&atid=527487"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2012-July/083853.html"},{"type":"REPORT","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=771360"}],"affected":[{"package":{"name":"claws-mail","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/claws-mail?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.11.1-1.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0531.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}