5.1
CVSSv2

CVE-2010-2801

Published: 09/08/2010 Updated: 26/04/2021
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer signedness error in the Quantum decompressor in cabextract prior to 1.3, when archive test mode is used, allows user-assisted remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.

Vulnerable Product Search on Vulmon Subscribe to Product

cabextract project cabextract 1.1

cabextract project cabextract 1.0

cabextract project cabextract 0.6

cabextract project cabextract 0.5

cabextract project cabextract

cabextract project cabextract 0.2

cabextract project cabextract 0.1

cabextract project cabextract 0.4

cabextract project cabextract 0.3

Vendor Advisories

Debian Bug report logs - #591552 Two security issues Package: cabextract; Maintainer for cabextract is Eric Sharkey <sharkey@debianorg>; Source for cabextract is src:cabextract (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 3 Aug 2010 21:09:01 UTC Severity: grave Tags: security ...
It was discovered that a programming error in the archive test mode of cabextract, a program to extract Microsoft Cabinet files, could lead to the execution of arbitrary code For the stable distribution (lenny), this problem has been fixed in version 12-3+lenny1 For the unstable distribution (sid), this problem will be fixed soon We recommend t ...