In mspack/cab.h in libmspack before 0.8alpha and...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Oct 23, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 2, 2023
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
References