In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade advancecomp | Jun 16, 2020 | Feb 27, 2019 |
| Amazon Linux Ami 2 | — | Upgrade advancecomp-debuginfoUpgrade advancecomp | Jul 21, 2020 | Feb 27, 2019 |
| Centos_linux | — | Upgrade advancecomp-debuginfoUpgrade advancecomp | Apr 1, 2020 | Feb 27, 2019 |
| Debian | — | Upgrade advancecomp | Mar 12, 2019 | Feb 27, 2019 |
| Freebsd | — | Upgrade advancecomp | Nov 4, 2022 | Nov 19, 2021 |
| Oracle_linux | — | Upgrade advancecomp | Oct 5, 2022 | Feb 27, 2019 |
| Redhat_linux | — | Upgrade advancecomp-debuginfoUpgrade advancecomp | Apr 1, 2020 | Feb 27, 2019 |
| Ubuntu | — | Upgrade advancecomp | Apr 10, 2019 | Feb 27, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub