5

CVE-2014-9556

Exploit
Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file, which triggers an infinite loop.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libmspack Project ≫ Libmspack Version 0.4
   Opensuse ≫ Opensuse Version 13.1
   Opensuse ≫ Opensuse Version 13.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.82% 0.847
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://advisories.mageia.org/MGASA-2015-0052.html
http://lists.opensuse.org/opensuse-updates/2015-02/msg00004.html
http://secunia.com/advisories/62793
http://www.mandriva.com/security/advisories?name=MDVSA-2015:041
http://www.openwall.com/lists/oss-security/2015/01/01/5
http://www.openwall.com/lists/oss-security/2015/01/07/2
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773041
Exploit