4.3
CVSSv2

CVE-2010-2800

Published: 09/08/2010 Updated: 26/04/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The MS-ZIP decompressor in cabextract prior to 1.3 allows remote malicious users to cause a denial of service (infinite loop) via a malformed MSZIP archive in a .cab file during a (1) test or (2) extract action, related to the libmspack library.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cabextract project cabextract 0.4

cabextract project cabextract 0.2

cabextract project cabextract

cabextract project cabextract 1.1

cabextract project cabextract 1.0

cabextract project cabextract 0.6

cabextract project cabextract 0.5

cabextract project cabextract 0.3

cabextract project cabextract 0.1

Vendor Advisories

Debian Bug report logs - #591552 Two security issues Package: cabextract; Maintainer for cabextract is Eric Sharkey <sharkey@debianorg>; Source for cabextract is src:cabextract (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 3 Aug 2010 21:09:01 UTC Severity: grave Tags: security ...