Severity
7.8HIGHNVD
EPSS
0.3%
top 45.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 17
Latest updateOct 12

Description

An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

Also affects: Debian Linux 9.0, Fedora 30, Enterprise Linux 7.0

🔴Vulnerability Details

4
OSV
advancecomp vulnerabilities2022-10-12
GHSA
GHSA-7hv8-6cmq-gcwj: An issue was discovered in AdvanceCOMP through 22022-05-13
CVEList
CVE-2019-8383: An issue was discovered in AdvanceCOMP through 22019-02-17
OSV
CVE-2019-8383: An issue was discovered in AdvanceCOMP through 22019-02-17

📋Vendor Advisories

4
Ubuntu
AdvanceCOMP vulnerabilities2022-10-12
Red Hat
advancecomp: denial of service in function adv_png_unfilter_8 in lib/png.c2019-02-16
Debian
CVE-2019-8383: advancecomp - An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address oc...2019
Red Hat
webkitgtk: processing maliciously crafted web content lead to URI spoofing2018-09-11

💬Community

2
Bugzilla
CVE-2019-8383 advancecomp: denial of service in function adv_png_unfilter_8 in lib/png.c [fedora-all]2019-05-10
Bugzilla
CVE-2019-8383 advancecomp: denial of service in function adv_png_unfilter_8 in lib/png.c2019-05-10
CVE-2019-8383 — Advancemame Advancecomp vulnerability | cvebase