CVE-2010-2801
09.08.2010, 11:58
Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.Enginsight
| Vendor | Product | Version |
|---|---|---|
| cabextract_project | cabextract | 𝑥 ≤ 1.2 |
| cabextract_project | cabextract | 0.1 |
| cabextract_project | cabextract | 0.2 |
| cabextract_project | cabextract | 0.3 |
| cabextract_project | cabextract | 0.4 |
| cabextract_project | cabextract | 0.5 |
| cabextract_project | cabextract | 0.6 |
| cabextract_project | cabextract | 1.0 |
| cabextract_project | cabextract | 1.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References