CVE-2010-2801Project Cabextract vulnerability

CWE-1897 documents6 sources
Severity
5.1MEDIUMNVD
EPSS
5.0%
top 10.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 9
Latest updateMay 13

Description

Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xw7m-8mhm-xjcv: Integer signedness error in the Quantum decompressor in cabextract before 12022-05-13
OSV
CVE-2010-2801: Integer signedness error in the Quantum decompressor in cabextract before 12010-08-09
CVEList
CVE-2010-2801: Integer signedness error in the Quantum decompressor in cabextract before 12010-08-06

📋Vendor Advisories

1
Debian
CVE-2010-2801: cabextract - Integer signedness error in the Quantum decompressor in cabextract before 1.3, w...2010

💬Community

2
Bugzilla
CVE-2010-2800 CVE-2010-2801 cabextract various flaws [fedora-all]2010-08-02
Bugzilla
CVE-2010-2801 cabextract: Integer wrap-around (crash) by processing certain *.cab files in test archive mode2010-08-02
CVE-2010-2801 — Project Cabextract vulnerability | cvebase