CVE-2017-6802: Debian Linux

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Ytnef Project Ytnef: up to and including 1.9.1

Published 2017-03-10. Last modified 2026-06-17.