yTNEF Multiple Buffer Overflow and Directory Traversal Vulnerabilities
Description
Multiple vulnerabilities have been identified in yTNEF, which could be exploited by attackers to compromise a vulnerable system.
The first issue is caused by buffer overflow errors when parsing an overly long filename (more than 256 bytes) in the TNEF data structure, which could allow attackers to crash an affected application or execute arbitrary code.
The second vulnerability is caused by an input validation error when processing the file names of attachments, which could allow attackers to overwrite arbitrary files by tricking a user into saving a malicious attachment.