libyal/libpff

libyal/libpff

Releases4
Frequency1 year 9 months
Last Release
Stars356
Library and tools to access the Personal Folder File (PFF) and the Offline Folder File (OFF) format

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH4.4 MEDIUM

An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.

1.9 LOW

libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service (infinite recursion) via a crafted file, related to libfdata_tree_get_node_value in libfdata_tree.c.