cbcvebase.
CVE-2010-2801
published 2010-08-09

CVE-2010-2801: Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a…

PriorityP424medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
4.03%
89.5th percentile
Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.

Affected

14 ranges
VendorProductVersion rangeFixed in
cabextract_projectcabextract<= 1.2
cabextract_projectcabextract
cabextract_projectcabextract
cabextract_projectcabextract
cabextract_projectcabextract
cabextract_projectcabextract
cabextract_projectcabextract
cabextract_projectcabextract
cabextract_projectcabextract
cabextract_projectcabextract>= 0 < 1.3-11.3-1
cabextract_projectcabextract>= 0 < 1.3-11.3-1
cabextract_projectcabextract>= 0 < 1.3-11.3-1
cabextract_projectcabextract>= 0 < 1.3-11.3-1
debiancabextract< cabextract 1.3-1 (bookworm)cabextract 1.3-1 (bookworm)

CVSS provenance

nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.