Hi, The following vulnerabilities were published for tnef. CVE-2026-103678[0]: | A flaw was found in tnef. An attacker can exploit this vulnerability | by providing a specially crafted file containing uncompressed Rich | Text Format (RTF) data. Because the application fails to properly | validate input buffer boundaries before copying data in | get_rtf_data_from_buf(), reading beyond the allocated memory occurs. | This flaw can cause the application to crash, leading to a Denial of | Service (DoS), or leak sensitive memory contents into extracted | output files. CVE-2026-103679[1]: | A flaw was found in tnef. A remote attacker could exploit this | vulnerability by providing a specially crafted Transport Neutral | Encapsulation Format (TNEF) file containing multiple message bodies. | During extraction, improper memory management triggers a use-after- | free and double-free condition, causing the application to crash and | resulting in a Denial of Service (DoS). CVE-2026-103680[2]: | A flaw was found in tnef. A heap-based buffer overflow can occur in | the find_free_number() function when generating numbered backup | suffixes for duplicate filenames. When numbered backups are enabled | and file overwriting is disabled, an attacker can supply a specially | crafted Transport Neutral Encapsulation Format (TNEF) file with an | excessive number of colliding attachment filenames, causing the | numeric counter to write past the allocated memory buffer. This | issue may result in an application crash, leading to a Denial of | Service (DoS), or potentially arbitrary code execution. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-103678 https://www.cve.org/CVERecord?id=CVE-2026-103678 [1] https://security-tracker.debian.org/tracker/CVE-2026-103679 https://www.cve.org/CVERecord?id=CVE-2026-103679 [2] https://security-tracker.debian.org/tracker/CVE-2026-103680 https://www.cve.org/CVERecord?id=CVE-2026-103680 Please adjust the affected versions in the BTS as needed. Regards, Salvatore