CVE-2010-2800Infinite Loop in Project Cabextract

CWE-3997 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
1.2%
top 21.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 9
Latest updateMay 13

Description

The MS-ZIP decompressor in cabextract before 1.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed MSZIP archive in a .cab file during a (1) test or (2) extract action, related to the libmspack library.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-j7gx-hgxw-46mm: The MS-ZIP decompressor in cabextract before 12022-05-13
OSV
CVE-2010-2800: The MS-ZIP decompressor in cabextract before 12010-08-09
CVEList
CVE-2010-2800: The MS-ZIP decompressor in cabextract before 12010-08-06

📋Vendor Advisories

1
Debian
CVE-2010-2800: cabextract - The MS-ZIP decompressor in cabextract before 1.3 allows remote attackers to caus...2010

💬Community

2
Bugzilla
CVE-2010-2800 CVE-2010-2801 cabextract various flaws [fedora-all]2010-08-02
Bugzilla
CVE-2010-2800 cabextract: Infinite loop in MS-ZIP and Quantum decoders2010-08-02
CVE-2010-2800 — Infinite Loop in Project Cabextract | cvebase