CVE-2022-35016
published 2022-08-29CVE-2022-35016: Advancecomp v2.3 was discovered to contain a heap buffer overflow.
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.45%
36.3th percentile
Advancecomp v2.3 was discovered to contain a heap buffer overflow.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advancemame | advancecomp | — | — |
| advancemame | advancecomp | >= 0 < 2.4-1 | 2.4-1 |
| advancemame | advancecomp | >= 0 < 2.4-1 | 2.4-1 |
| advancemame | advancecomp | >= 0 < 2.4-1 | 2.4-1 |
| advancemame | advancecomp | >= 0 < 2.1-1ubuntu0.18.04.3 | 2.1-1ubuntu0.18.04.3 |
| advancemame | advancecomp | >= 0 < 2.1-2.1ubuntu0.20.04.1 | 2.1-2.1ubuntu0.20.04.1 |
| advancemame | advancecomp | >= 0 < 2.1-2.1ubuntu2.1 | 2.1-2.1ubuntu2.1 |
| advancemame | advancecomp | >= 0 < 1.20-1ubuntu0.2+esm2 | 1.20-1ubuntu0.2+esm2 |
| debian | advancecomp | < advancecomp 2.4-1 (bookworm) | advancecomp 2.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
advancecomp vulnerabilities
osv·2023-02-01·CVSS 5.5
CVE-2022-35014 [MEDIUM] advancecomp vulnerabilities
advancecomp vulnerabilities
It was discovered that AdvanceCOMP did not properly manage memory while
performing read operations on MNG file. If a user were tricked into opening
a specially crafted MNG file, a remote attacker could possibly use this
issue to cause AdvanceCOMP to crash, resulting in a denial of service.
(CVE-2022-35014, CVE-2022-35017, CVE-2022-35018, CVE-2022-35019,
CVE-2022-35020)
It was discovered that AdvanceCOMP did not properly manage memory while
performing read operations on ZIP file. If a user were tricked into opening
a specially crafted ZIP file, a remote attacker could possibly use this
issue to cause AdvanceCOMP to crash, resulting in a denial of service.
(CVE-2022-35015, CVE-2022-35016)
OSV
CVE-2022-35016: Advancecomp v2
osv·2022-08-29·CVSS 5.5
CVE-2022-35016 [MEDIUM] CVE-2022-35016: Advancecomp v2
Advancecomp v2.3 was discovered to contain a heap buffer overflow.
GHSA
GHSA-cwmf-5x7w-g67f: Advancecomp v2
ghsa_unreviewed·2022-08-29
CVE-2022-35016 [MEDIUM] CWE-787 GHSA-cwmf-5x7w-g67f: Advancecomp v2
Advancecomp v2.3 was discovered to contain a heap buffer overflow.
Ubuntu
AdvanceCOMP vulnerabilities
vendor_ubuntu·2023-02-01·CVSS 5.5
CVE-2022-35016 [MEDIUM] AdvanceCOMP vulnerabilities
Title: AdvanceCOMP vulnerabilities
Summary: Several security issues were fixed in AdvanceCOMP.
It was discovered that AdvanceCOMP did not properly manage memory while
performing read operations on MNG file. If a user were tricked into opening
a specially crafted MNG file, a remote attacker could possibly use this
issue to cause AdvanceCOMP to crash, resulting in a denial of service.
(CVE-2022-35014, CVE-2022-35017, CVE-2022-35018, CVE-2022-35019,
CVE-2022-35020)
It was discovered that AdvanceCOMP did not properly manage memory while
performing read operations on ZIP file. If a user were tricked into opening
a specially crafted ZIP file, a remote attacker could possibly use this
issue to cause AdvanceCOMP to crash, resulting in a denial of service.
(CVE-2022-35015, CVE-2022-35016)
Instr
Red Hat
advancecomp: heap buffer overflow in data_dup() in data.cc
vendor_redhat·2022-08-29·CVSS 5.5
CVE-2022-35016 [MEDIUM] CWE-122 advancecomp: heap buffer overflow in data_dup() in data.cc
advancecomp: heap buffer overflow in data_dup() in data.cc
Advancecomp v2.3 was discovered to contain a heap buffer overflow.
A heap buffer overflow vulnerability was found in advancecomp in the data_dup() function of the data.cc file. This flaw allows an attacker to trick a user into opening a specially crafted file that could cause an application to crash, leading to a denial of service attack.
Package: advancecomp (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2022-35016: advancecomp - Advancecomp v2.3 was discovered to contain a heap buffer overflow.
vendor_debian·2022·CVSS 5.5
CVE-2022-35016 [MEDIUM] CVE-2022-35016: advancecomp - Advancecomp v2.3 was discovered to contain a heap buffer overflow.
Advancecomp v2.3 was discovered to contain a heap buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.4-1)
bullseye: open
forky: resolved (fixed in 2.4-1)
sid: resolved (fixed in 2.4-1)
trixie: resolved (fixed in 2.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://drive.google.com/file/d/1oWVhoJJih6-pgbvrZsx5oFUtv-vgR0fF/view?usp=sharinghttps://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35016.mdhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYG2XAL4MBS7ADGJWYRUKBLDTBJFPJER/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQHLMLFHPV5C7PTBZML6U72QT6VNEOEF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XP42AC5VPTY45QKMRL3W4G4EXIUMFXRE/https://drive.google.com/file/d/1oWVhoJJih6-pgbvrZsx5oFUtv-vgR0fF/view?usp=sharinghttps://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35016.mdhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYG2XAL4MBS7ADGJWYRUKBLDTBJFPJER/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQHLMLFHPV5C7PTBZML6U72QT6VNEOEF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XP42AC5VPTY45QKMRL3W4G4EXIUMFXRE/
2022-08-29
Published