CVE-2009-3721

HIGHCVSS 7.8/10EPSS 1.61%

Last modified

CVE-2009-3721 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.. EPSS estimates a 1.61% chance of exploitation in the next 30 days.

Description

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
1.61%

72.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GnomeEvolutionAll versions
Ytnef ProjectYtnefAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2009-3721?
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.
How severe is CVE-2009-3721?
CVE-2009-3721 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 1.61% probability of exploitation in the next 30 days.
How do I fix CVE-2009-3721?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2009-3721?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST