VDB

CVE-2014-9732

CVE-2014-9732 PUBLISHED

The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive.

EPSS 7.16% · 93.9th percentile

Risk Scores

EPSS Score
7.16%
93.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlibmspack0, 0.4-1
Ubuntu:Pro:14.04:LTScabextract1.4-4, 0

Timeline

  • CVE Published
  • Jun 30, 2016 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 26, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›