REDHAT-BUG-620450: Low severity Gentoo cabextract vulnerability
A deficiency has been reported in the way cabextract extracted certain Cabinet (.cab) files, using the MZ-ZIP and Quantum decompressors. If a local user was tricked into opening a specially-crafted .cab file, it could lead to infinite loop.
References: [1] http://bugs.gentoo.org/showbug.cgi?id=329891
Upstream patches: [2] http://libmspack.svn.sourceforge.net/viewvc/libmspack?view=revision&revision=90 [3] http://libmspack.svn.sourceforge.net/viewvc/libmspack?view=revision&revision=95 [4] http://libmspack.svn.sourceforge.net/viewvc/libmspack/libmspack/trunk/mspack/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-620450?
The severity of REDHAT-BUG-620450 is high due to the potential for a local user to be tricked into causing an infinite loop by opening a specially-crafted cabinet file.
How do I fix REDHAT-BUG-620450?
To fix REDHAT-BUG-620450, update to the latest version of cabextract or libmspack that addresses this vulnerability.
What software is affected by REDHAT-BUG-620450?
REDHAT-BUG-620450 affects Gentoo cabextract and libmspack.
What is the impact of REDHAT-BUG-620450?
The impact of REDHAT-BUG-620450 includes the possibility of a denial of service due to an infinite loop when processing certain cabinet files.
Who can exploit REDHAT-BUG-620450?
An attacker can exploit REDHAT-BUG-620450 by tricking a local user into opening a malicious cabinet file.