CVE-2014-9732Project Libmspack vulnerability

6 documents6 sources
Severity
4.3MEDIUMNVD
EPSS
0.4%
top 39.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 17

Description

The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-f9hg-4282-x667: The cabd_extract function in cabd2022-05-17
OSV
CVE-2014-9732: The cabd_extract function in cabd2015-06-11
CVEList
CVE-2014-9732: The cabd_extract function in cabd2015-06-11

📋Vendor Advisories

1
Debian
CVE-2014-9732: libmspack - The cabd_extract function in cabd.c in libmspack before 0.5 does not properly ma...2014

💬Community

1
Bugzilla
CVE-2014-9732 cabextract: null pointer dereference on a crafted CAB2015-02-25
CVE-2014-9732 — Project Libmspack vulnerability | cvebase