** DISPUTED ** The libpffnametoidmapentryread function in libpffnametoidmap.c in libyal libpff through 2018-04-28 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted pff file. NOTE: the vendor has disputed this as described in libyal/libpff issue 66 on GitHub.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libpff-dev",
"binary_version": "20180714-1"
},
{
"binary_name": "libpff1",
"binary_version": "20180714-1"
},
{
"binary_name": "libpff1-dbgsym",
"binary_version": "20180714-1"
},
{
"binary_name": "pff-tools",
"binary_version": "20180714-1"
},
{
"binary_name": "pff-tools-dbgsym",
"binary_version": "20180714-1"
}
]
}