CVE-2014-9274
unrtf - security update
EPSS 5.8%
Description
UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999".
How to fix CVE-2014-9274
To remediate CVE-2014-9274, upgrade the affected package to a fixed version below.
- Debian/unrtf—upgrade to 0.21.5-2 or later
- Debian/unrtf—upgrade to 0.19.3-1.1+deb6u1 or later
- Debian/unrtf—upgrade to 0.21.5-3~deb7u1 or later
Is CVE-2014-9274 being exploited?
Moderate — EPSS is 5.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 0.21.5-2
- from 0, < 0.19.3-1.1+deb6u1
- from 0, < 0.21.5-3~deb7u1