CVE-2010-2801: Medium severity Cabextract Project Cabextract vulnerability
An integer wrap-around flaw has been reported in the way cabextract processed certain Cabinet (.cab) archive files. If a local user was tricked into opening a specially-crafted .cab archive in test archive mode, it could lead to cabextract executable crash.
References: [1] http://bugs.gentoo.org/showbug.cgi?id=329891
Upstream patches: [2] http://libmspack.svn.sourceforge.net/viewvc/libmspack/libmspack/trunk/mspack/qtmd.c?r1=114&r2=113 [3] http://libmspack.svn.sourceforge.net/viewvc/libmspack?view=revision&revision=118
Other sources
Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2801?
CVE-2010-2801 is classified as a moderate severity vulnerability due to the potential for application crashes.
How do I fix CVE-2010-2801?
To mitigate CVE-2010-2801, users should upgrade to a version of cabextract later than 1.2.
What causes the vulnerability in CVE-2010-2801?
CVE-2010-2801 is caused by an integer wrap-around flaw when processing certain specially-crafted Cabinet archive files.
Who is affected by CVE-2010-2801?
CVE-2010-2801 affects users of cabextract versions 0.1 to 1.2.
What type of attack is possible with CVE-2010-2801?
An attacker could use CVE-2010-2801 to craft a malicious cabinet file that, when opened, results in a crash of the cabextract executable.