[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-9556Date: (C)2015-02-04   (M)2023-12-22


Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file, which triggers an infinite loop.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECUNIA-62793
MDVSA-2015:041
http://www.openwall.com/lists/oss-security/2015/01/01/5
http://www.openwall.com/lists/oss-security/2015/01/07/2
http://advisories.mageia.org/MGASA-2015-0052.html
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773041
openSUSE-SU-2015:0187

CPE    2
cpe:/o:opensuse:opensuse:13.1
cpe:/a:libmspack_project:libmspack:0.4
CWE    1
CWE-189
OVAL    2
oval:org.secpod.oval:def:108500
oval:org.secpod.oval:def:108498

© SecPod Technologies