The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted file, i.e., data is written to memory addresses before the beginning of the tmpBuf buffer.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:0.94.3~git20160113.dbc9ec6+dfsg-1+deb9u1build0.16.04.1", "binary_name": "catdoc" }, { "binary_version": "1:0.94.3~git20160113.dbc9ec6+dfsg-1+deb9u1build0.16.04.1", "binary_name": "catdoc-dbgsym" } ] }