Buffer overflow in AdvanceCOMP - CVE-2019-8383
Published: February 17, 2019 / Updated: July 17, 2020
Vulnerability details
The vulnerability allows a local non-authenticated attacker to execute arbitrary code.
An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.
Affected software
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Ubuntu
Fedora
advancecomp (Ubuntu package)
advancecomp (Red Hat package)
advancecomp
How to mitigate CVE-2019-8383
advancecomp (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.1-1ubuntu0.18.04.2
advancecomp (Red Hat package) - update to 1.15-21.el7
advancecomp - update to 2.1-11.fc30
External References
- https://access.redhat.com/errata/RHSA-2019:2332
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J23C6QSTJMQ467KAI6QG54AE4MZRLPQV/
- https://research.loginsoft.com/bugs/invalid-memory-access-in-adv_png_unfilter_8-advancecomp/
- https://sourceforge.net/p/advancemame/bugs/272/