Out-of-bounds read in AdvanceCOMP - CVE-2018-1056
Published: July 27, 2018 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.
Affected software
Fedora
advancecomp
How to mitigate CVE-2018-1056
advancecomp - addressed in versions 2.1-4.fc27, 2.1-4.fc28
External References
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889270
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1056
- https://lists.debian.org/debian-lts-announce/2018/02/msg00016.html
- https://lists.debian.org/debian-lts-announce/2019/03/msg00004.html
- https://sourceforge.net/p/advancemame/bugs/259/
- https://usn.ubuntu.com/3570-1/