CVE-2010-2801

Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
cabextract_projectcabextract
𝑥
≤ 1.2
cabextract_projectcabextract
0.1
cabextract_projectcabextract
0.2
cabextract_projectcabextract
0.3
cabextract_projectcabextract
0.4
cabextract_projectcabextract
0.5
cabextract_projectcabextract
0.6
cabextract_projectcabextract
1.0
cabextract_projectcabextract
1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cabextract
bookworm
1.9-3
fixed
bullseye
1.9-3
fixed
sid
1.11-2
fixed
trixie
1.11-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cabextract
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
Fixed 1.2-3+lenny1build0.10.04.1
released
karmic
Fixed 1.2-3+lenny1build0.9.10.1
released
jaunty
Fixed 1.2-3+lenny1build0.9.04.1
released
hardy
ignored
dapper
ignored
Common Weakness Enumeration