An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade emacs-mercurial-elUpgrade mercurial-debuginfoUpgrade advancecompUpgrade advancecomp-debuginfoUpgrade mercurialUpgrade emacs-mercurialUpgrade mercurial-hgk | Apr 27, 2020 | Feb 17, 2019 |
| Centos_linux | — | Upgrade advancecomp-debuginfoUpgrade advancecomp | Aug 28, 2019 | Feb 17, 2019 |
| Debian | — | Upgrade advancecomp | Jan 4, 2022 | Feb 17, 2019 |
| Freebsd | — | Upgrade advancecomp | Nov 4, 2022 | Nov 19, 2021 |
| Oracle_linux | — | Upgrade advancecomp | Jul 21, 2020 | Feb 16, 2019 |
| Redhat_linux | — | Upgrade advancecomp-debuginfoUpgrade advancecomp | Aug 7, 2019 | Feb 17, 2019 |
| Ubuntu | — | Upgrade advancecomp (Ubuntu Pro)Upgrade advancecomp | Oct 12, 2022 | Feb 16, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub