CVE-2019-18849

CVE-2019-18849

In tnef before 1.4.18, an attacker may be able to write to the victim’s .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.

Source: CVE-2019-18849

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다