CVE-2019-8383 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Advancecomp
Severity
7.8HIGHNVD
EPSS
0.3%
top 45.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 17
Latest updateOct 12
Description
An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages5 packages
Also affects: Debian Linux 9.0, Fedora 30, Enterprise Linux 7.0
🔴Vulnerability Details
4📋Vendor Advisories
4Debian▶
CVE-2019-8383: advancecomp - An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address oc...↗2019