PT-2019-19002 · Advancecomp+4 · Advancecomp+4

Ace Team

·

Published

2019-02-17

·

Updated

2024-09-04

·

CVE-2019-8383

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AdvanceCOMP versions prior to 2.1
Description An issue was discovered that can cause an invalid memory address to occur in the adv png unfilter 8 function in lib/png.c. This can be triggered by sending a crafted file to a binary, allowing an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.
Recommendations For AdvanceCOMP versions prior to 2.1, consider updating to a version that fixes the issue in the adv png unfilter 8 function. As a temporary workaround, consider restricting the use of the lib/png.c module to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6301
ALT-PU-2024-11930
CESA-2019_2332
CVE-2019-8383
DLA-2868-1
MGASA-2020-0008
RHSA-2019:2332
RHSA-2019_2332
USN-5671-1

Affected Products

Alt Linux
Advancecomp
Centos
Red Hat
Ubuntu