CVE-2014-9556
published 2015-02-03CVE-2014-9556: Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file, which…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.82%
85.0th percentile
Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file, which triggers an infinite loop.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cabextract_project | cabextract | >= 0 < 1.4-5 | 1.4-5 |
| cabextract_project | cabextract | >= 0 < 1.4-5 | 1.4-5 |
| cabextract_project | cabextract | >= 0 < 1.4-5 | 1.4-5 |
| cabextract_project | cabextract | >= 0 < 1.4-5 | 1.4-5 |
| debian | cabextract | < cabextract 1.4-5 (bookworm) | cabextract 1.4-5 (bookworm) |
| debian | libmspack | < cabextract 1.4-5 (bookworm) | cabextract 1.4-5 (bookworm) |
| libmspack_project | libmspack | — | — |
| libmspack_project | libmspack | >= 0 < 0.4-2 | 0.4-2 |
| libmspack_project | libmspack | >= 0 < 0.4-2 | 0.4-2 |
| libmspack_project | libmspack | >= 0 < 0.4-2 | 0.4-2 |
| libmspack_project | libmspack | >= 0 < 0.4-2 | 0.4-2 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9768-cv3h-4v3f: Integer overflow in the qtmd_decompress function in libmspack 0
ghsa_unreviewed·2022-05-14
CVE-2014-9556 [MEDIUM] GHSA-9768-cv3h-4v3f: Integer overflow in the qtmd_decompress function in libmspack 0
Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file, which triggers an infinite loop.
OSV
CVE-2014-9556: Integer overflow in the qtmd_decompress function in libmspack 0
osv·2015-02-03·CVSS 5.0
CVE-2014-9556 [MEDIUM] CVE-2014-9556: Integer overflow in the qtmd_decompress function in libmspack 0
Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file, which triggers an infinite loop.
Debian
CVE-2014-9556: cabextract - Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote ...
vendor_debian·2014·CVSS 5.0
CVE-2014-9556 [MEDIUM] CVE-2014-9556: cabextract - Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote ...
Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file, which triggers an infinite loop.
Scope: local
bookworm: resolved (fixed in 1.4-5)
bullseye: resolved (fixed in 1.4-5)
forky: resolved (fixed in 1.4-5)
sid: resolved (fixed in 1.4-5)
trixie: resolved (fixed in 1.4-5)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9556 libmspack: buffer overflow causing denial of service in qtmd_decompress() [fedora-all]
bugzilla·2015-01-07·CVSS 5.0
CVE-2014-9556 [MEDIUM] CVE-2014-9556 libmspack: buffer overflow causing denial of service in qtmd_decompress() [fedora-all]
CVE-2014-9556 libmspack: buffer overflow causing denial of service in qtmd_decompress() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2014-9556 libmspack: buffer overflow causing denial of service in qtmd_decompress() [epel-all]
bugzilla·2015-01-07·CVSS 5.0
CVE-2014-9556 [MEDIUM] CVE-2014-9556 libmspack: buffer overflow causing denial of service in qtmd_decompress() [epel-all]
CVE-2014-9556 libmspack: buffer overflow causing denial of service in qtmd_decompress() [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2014-9556 libmspack: buffer overflow causing denial of service in qtmd_decompress()
bugzilla·2015-01-05·CVSS 5.0
CVE-2014-9556 [MEDIUM] CVE-2014-9556 libmspack: buffer overflow causing denial of service in qtmd_decompress()
CVE-2014-9556 libmspack: buffer overflow causing denial of service in qtmd_decompress()
It was reported [1] that a binary using libmspack will hang when processing a crafted .CAB file.
Upstream patch that fixes this:
http://anonscm.debian.org/cgit/collab-maint/libmspack.git/tree/debian/patches/qtmd-fix-frame_end-overflow.patch
CVE requested at: http://seclists.org/oss-sec/2015/q1/4
[1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773041
Discussion:
(In reply to Vasyl Kaigorodov from comment #0)
> It was reported [1] that a binary using libmspack will hang when processing
> a crafted .CAB file.
> Upstream patch that fixes this:
> http://anonscm.debian.org/cgit/collab-maint/libmspack.git/tree/debian/
> patches/qtmd-fix-frame_end-overflow.patch
it is a local Debian patch, not upst
http://advisories.mageia.org/MGASA-2015-0052.htmlhttp://lists.opensuse.org/opensuse-updates/2015-02/msg00004.htmlhttp://secunia.com/advisories/62793http://www.mandriva.com/security/advisories?name=MDVSA-2015:041http://www.openwall.com/lists/oss-security/2015/01/01/5http://www.openwall.com/lists/oss-security/2015/01/07/2https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773041http://advisories.mageia.org/MGASA-2015-0052.htmlhttp://lists.opensuse.org/opensuse-updates/2015-02/msg00004.htmlhttp://secunia.com/advisories/62793http://www.mandriva.com/security/advisories?name=MDVSA-2015:041http://www.openwall.com/lists/oss-security/2015/01/01/5http://www.openwall.com/lists/oss-security/2015/01/07/2https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773041
2015-02-03
Published