An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade emacs-mercurial-elUpgrade mercurialUpgrade mercurial-hgkUpgrade advancecompUpgrade mercurial-debuginfoUpgrade emacs-mercurialUpgrade advancecomp-debuginfo | Apr 27, 2020 | Feb 17, 2019 |
| Centos_linux | — | Upgrade advancecomp-debuginfoUpgrade advancecomp | Aug 28, 2019 | Feb 17, 2019 |
| Debian | — | Upgrade advancecomp | Jan 4, 2022 | Feb 17, 2019 |
| Freebsd | — | Upgrade advancecomp | Nov 4, 2022 | Nov 19, 2021 |
| Oracle_linux | — | Upgrade advancecomp | Jul 21, 2020 | Feb 16, 2019 |
| Redhat_linux | — | Upgrade advancecompUpgrade advancecomp-debuginfo | Aug 7, 2019 | Feb 17, 2019 |
| Ubuntu | — | Upgrade advancecomp (Ubuntu Pro)Upgrade advancecomp | Oct 12, 2022 | Feb 16, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub