CVE-2014-9732: Null Pointer Dereference
The cabdextract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9732?
CVE-2014-9732 is classified as a denial of service vulnerability due to NULL pointer dereference leading to application crashes.
How do I fix CVE-2014-9732?
To fix CVE-2014-9732, update libmspack to version 0.5 or later where the issue has been resolved.
What is the impact of CVE-2014-9732?
The impact of CVE-2014-9732 allows remote attackers to crash the application, leading to service disruption.
Which versions of libmspack are affected by CVE-2014-9732?
CVE-2014-9732 affects libmspack versions up to and including 0.4-3.
Can CVE-2014-9732 be exploited remotely?
Yes, CVE-2014-9732 can be exploited remotely by sending a crafted CAB archive to the vulnerable application.