
libyal/libpff
Releases4
Frequency1 year 9 months
Last Release
Stars356
Library and tools to access the Personal Folder File (PFF) and the Offline Folder File (OFF) format
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 7.8 HIGH | 4.4 MEDIUM | ||
An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file. | |||
| — | 1.9 LOW | ||
libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service (infinite recursion) via a crafted file, related to libfdata_tree_get_node_value in libfdata_tree.c. | |||