Back to Database
Status published
Medium
CVE-2014-9556
Integer overflow in the qtmd_decompress function in libmspack 0.4 allows...
Vulnerability Description
Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file, which triggers an infinite loop.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9556
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2015/01/01/5
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773041
- http://secunia.com/advisories/62793
- http://advisories.mageia.org/MGASA-2015-0052.html
- http://www.openwall.com/lists/oss-security/2015/01/07/2
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00004.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:041
More from libmspack project
View All →CVE-2017-6419
mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows...
High
7.8
CVE-2017-11423
The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used...
Medium
5.5
CVE-2015-4472
Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack...
Medium
6.8
CVE-2015-4471
Off-by-one error in the lzxd_decompress function in lzxd.c in libmspack...
Medium
4.3
CVE-2015-4470
Off-by-one error in the inflate function in mszipd.c in libmspack...
Medium
4.3
Affected Vendor
libmspack project
View all reports →Affected Software
libmspack
Vulnerable Versions:
0.4
Timeline
Official Publish:
February 3rd, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.