CVE-2010-2801
EPSS 5.0%cabextract - arbitrary code execution
發布日:2010/8/9修改日:2026/4/28
也稱為:DEBIAN-CVE-2010-2801
描述
Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.
受影響套件(2)
- Debian/cabextractfrom 0, < 1.3-1
- Debian/cabextractfrom 0, < 1.2-3+lenny1