CVE
- Id
- 77033
- CVE No.
- CVE-2014-9732
- Status
- Candidate
- Description
- The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certain cases where an invalid file follows a valid file, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted CAB archive.
- Phase
- Assigned (20150611)
- Votes
- None (candidate not yet proposed)
- Comments