Buffer overflow in AdvanceCOMP - CVE-2019-8383

 

Buffer overflow in AdvanceCOMP - CVE-2019-8383

Published: February 17, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU31157
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-8383
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to execute arbitrary code.

An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.


Affected software

AdvanceCOMP
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Ubuntu
Fedora
advancecomp (Ubuntu package)
advancecomp (Red Hat package)
advancecomp

How to mitigate CVE-2019-8383

Install update from vendor's website.

AdvanceCOMP - update to 2.1
advancecomp (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.1-1ubuntu0.18.04.2
advancecomp (Red Hat package) - update to 1.15-21.el7
advancecomp - update to 2.1-11.fc30

External References

Related Security Bulletins