CVE-2010-2800

The MS-ZIP decompressor in cabextract before 1.3 allows remote attackers to cause a denial of service (infinite loop) via a malformed MSZIP archive in a .cab file during a (1) test or (2) extract action, related to the libmspack library.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
cabextract_projectcabextract
𝑥
≤ 1.2
cabextract_projectcabextract
0.1
cabextract_projectcabextract
0.2
cabextract_projectcabextract
0.3
cabextract_projectcabextract
0.4
cabextract_projectcabextract
0.5
cabextract_projectcabextract
0.6
cabextract_projectcabextract
1.0
cabextract_projectcabextract
1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cabextract
bookworm
1.9-3
fixed
bullseye
1.9-3
fixed
sid
1.11-2
fixed
trixie
1.11-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cabextract
dapper
ignored
hardy
ignored
jaunty
ignored
karmic
ignored
lucid
ignored
maverick
not-affected
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libmspack-devel
suse enterprise desktop 15
0.6-1.17
fixed
suse enterprise desktop 15 SP1
0.6-3.3.11
fixed
suse enterprise sap 15
0.6-1.17
fixed
suse enterprise sap 15 SP1
0.6-3.3.11
fixed
suse enterprise server 15
0.6-1.17
fixed
suse enterprise server 15 SP1
0.6-3.3.11
fixed
libmspack0
suse enterprise desktop 15
0.6-1.17
fixed
suse enterprise desktop 15 SP1
0.6-3.3.11
fixed
suse enterprise sap 15
0.6-1.17
fixed
suse enterprise sap 15 SP1
0.6-3.3.11
fixed
suse enterprise server 15
0.6-1.17
fixed
suse enterprise server 15 SP1
0.6-3.3.11
fixed
Common Weakness Enumeration