⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2018-1056Heap-based Buffer Overflow in Advancecomp

Severity
7.8HIGHNVD
EPSS
0.4%
top 38.19%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJul 27
Latest updateMay 13

Description

An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianadvancemame/advancecomp< 2.1-1+3
CVEListV5amadvance/advancecomp2.1-2018/02

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10

🔴Vulnerability Details

3
GHSA
GHSA-557x-wcm4-fhw8: An out-of-bounds heap buffer read flaw was found in the way advancecomp before 22022-05-13
OSV
CVE-2018-1056: An out-of-bounds heap buffer read flaw was found in the way advancecomp before 22018-07-27
CVEList
CVE-2018-1056: An out-of-bounds heap buffer read flaw was found in the way advancecomp before 22018-07-27

📋Vendor Advisories

3
Ubuntu
AdvanceCOMP vulnerability2018-02-14
Red Hat
advancecomp: Heap buffer overflow in zip.cc:zip_entry::load_cent() allows for denial of service or unspecified impact via crafted ZIP file2018-02-03
Debian
CVE-2018-1056: advancecomp - An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2...2018

💬Community

2
Bugzilla
CVE-2018-1056 advancecomp: Heap buffer overflow in zip.cc:zip_entry::load_cent() allows for denial of service or unspecified impact via crafted ZIP file2018-02-06
Bugzilla
CVE-2018-1056 advancecomp: Heap buffer overflow in zip.cc:zip_entry::load_cent() allows for denial of service or unspecified impact via crafted ZIP file [fedora-all]2018-02-06
CVE-2018-1056 — Heap-based Buffer Overflow | cvebase