PT-2010-1018 · Cabextract+2 · Cabextract+2

Jan Lieskovsky

·

Publicado

2010-08-06

·

Atualizado

2021-04-26

·

CVE-2010-2801

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions cabextract versions prior to 1.3
Description The issue is related to an integer signedness error in the Quantum decompressor of cabextract. This error can be exploited by user-assisted remote attackers to cause a denial of service, resulting in an application crash, or possibly execute arbitrary code. The exploitation is possible via a crafted Quantum archive in a .cab file and is related to the libmspack library. The vulnerability may lead to a violation of confidentiality, integrity, and availability of protected information and can be exploited remotely.
Recommendations For versions prior to 1.3, update to version 1.3 or later to resolve the issue. As a temporary workaround, consider disabling the archive test mode in cabextract until a patch is available. Restrict access to crafted Quantum archives in .cab files to minimize the risk of exploitation.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02626
CVE-2010-2801
DSA-2087-1
OPENSUSE-SU-2024:10365-1

Produtos afetados

Suse
Cabextract
Libmspack