An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade emacs-mercurial-elUpgrade mercurial-hgkUpgrade mercurialUpgrade advancecompUpgrade advancecomp-debuginfoUpgrade emacs-mercurialUpgrade mercurial-debuginfo | Apr 27, 2020 | Feb 17, 2019 |
| Centos_linux | — | Upgrade advancecomp-debuginfoUpgrade advancecomp | Aug 28, 2019 | Feb 17, 2019 |
| Debian | — | Upgrade advancecomp | Jan 4, 2022 | Feb 17, 2019 |
| Freebsd | — | Upgrade advancecomp | Nov 4, 2022 | Nov 19, 2021 |
| Oracle_linux | — | Upgrade advancecomp | Jul 21, 2020 | Feb 16, 2019 |
| Redhat_linux | — | Upgrade advancecomp-debuginfoUpgrade advancecomp | Aug 7, 2019 | Feb 17, 2019 |
| Ubuntu | — | Upgrade advancecompUpgrade advancecomp (Ubuntu Pro) | Oct 12, 2022 | Feb 16, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub