Out-of-bounds read in AdvanceCOMP - CVE-2018-1056

 

Out-of-bounds read in AdvanceCOMP - CVE-2018-1056

Published: July 27, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36814
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1056
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.


Affected software

AdvanceCOMP
Fedora
advancecomp

How to mitigate CVE-2018-1056

Install update from vendor's website.

AdvanceCOMP - update to 2.1
advancecomp - addressed in versions 2.1-4.fc27, 2.1-4.fc28

External References

Related Security Bulletins