PT-2010-4302 · Cabextract+2 · Cabextract+2

Jan Lieskovsky

·

Published

2010-08-06

·

Updated

2021-04-26

·

CVE-2010-2800

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions cabextract versions prior to 1.3
Description The issue allows remote attackers to cause a denial of service, specifically an infinite loop, through a manipulated MSZIP file in a .cab file. This can occur during either a test or extract action and is related to the libmspack library.
Recommendations For versions prior to 1.3, update to version 1.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the MS-ZIP decompressor in cabextract until a patch is available. Avoid using the MS-ZIP decompressor with untrusted .cab files to minimize the risk of exploitation.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2800
OPENSUSE-SU-2024:10365-1
SUSE-SU-2014_0886-1

Affected Products

Suse
Cabextract
Libmspack