LWN.net Logo

cabextract: denial of service

Package(s):cabextract CVE #(s):CVE-2010-2800
Created:August 13, 2010 Updated:September 28, 2010
Description:

From the Pardus advisory:

The MS-ZIP decompressor in cabextract before 1.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed MSZIP archive in a .cab file during a (1) test or (2) extract action, related to the libmspack library.

Alerts:
Fedora FEDORA-2010-14634 2010-09-15
Fedora FEDORA-2010-14722 2010-09-15
Fedora FEDORA-2010-14634 2010-09-15
Fedora FEDORA-2010-14722 2010-09-15
Mandriva MDVSA-2010:154 2010-08-16
Pardus 2010-109 2010-08-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds