CVE-2010-2801
Publication date 9 August 2010
Last updated 24 July 2024
Ubuntu priority
Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Quantum archive in a .cab file, related to the libmspack library.
Status
Package | Ubuntu Release | Status |
---|---|---|
cabextract | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick |
Not affected
|
|
10.04 LTS lucid |
Fixed 1.2-3+lenny1build0.10.04.1
|
|
9.10 karmic |
Fixed 1.2-3+lenny1build0.9.10.1
|
|
9.04 jaunty |
Fixed 1.2-3+lenny1build0.9.04.1
|
|
8.04 LTS hardy | Ignored end of life | |
6.06 LTS dapper | Ignored end of life |
Patch details
Package | Patch details |
---|---|
cabextract |