Buffer overflow in AdvanceCOMP - CVE-2022-35014
Published: November 25, 2022
Vulnerability identifier: #VU69601
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-35014
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing archives. A remote attacker can create a specially crafted archive, trick the victim into opening it, trigger memory corruption and crash the application.
Affected software
AdvanceCOMP
Fedora
Ubuntu
advancecomp (Ubuntu package)
advancecomp
Fedora
Ubuntu
advancecomp (Ubuntu package)
advancecomp
How to mitigate CVE-2022-35014
Install updates from vendor's website.
AdvanceCOMP - update to 2.4
advancecomp (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.1-1ubuntu0.18.04.3, 2.1-2.1ubuntu0.20.04.1, 2.1-2.1ubuntu2.1, 2.3-1ubuntu0.22.10.1
advancecomp - addressed in versions 2.4-1.el8, 2.4-1.el9, 2.4-1.fc35, 2.4-1.fc36, 2.4-1.fc37
advancecomp (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.1-1ubuntu0.18.04.3, 2.1-2.1ubuntu0.20.04.1, 2.1-2.1ubuntu2.1, 2.3-1ubuntu0.22.10.1
advancecomp - addressed in versions 2.4-1.el8, 2.4-1.el9, 2.4-1.fc35, 2.4-1.fc36, 2.4-1.fc37