4.3
CVSSv2

CVE-2014-9732

Published: 11/06/2015 Updated: 28/11/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The cabd_extract function in cabd.c in libmspack prior to 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive.

Vulnerable Product Search on Vulmon Subscribe to Product

libmspack project libmspack

Vendor Advisories

Debian Bug report logs - #774665 libmspack: CVE-2014-9732: null pointer dereference on a crafted CAB Package: libmspack; Maintainer for libmspack is Marc Dequènes (Duck) <Duck@DuckCorporg>; Reported by: Jakub Wilk <jwilk@debianorg> Date: Sun, 21 Dec 2014 17:39:02 UTC Severity: normal Found in version 04-2 Fixed ...