CVE-2022-35019
published 2022-08-29CVE-2022-35019: Advancecomp v2.3 was discovered to contain a segmentation fault.
PriorityP415medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.43%
34.7th percentile
Advancecomp v2.3 was discovered to contain a segmentation fault.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advancemame | advancecomp | — | — |
| advancemame | advancecomp | >= 0 < 2.4-1 | 2.4-1 |
| advancemame | advancecomp | >= 0 < 2.4-1 | 2.4-1 |
| advancemame | advancecomp | >= 0 < 2.4-1 | 2.4-1 |
| advancemame | advancecomp | >= 0 < 2.1-1ubuntu0.18.04.3 | 2.1-1ubuntu0.18.04.3 |
| advancemame | advancecomp | >= 0 < 2.1-2.1ubuntu0.20.04.1 | 2.1-2.1ubuntu0.20.04.1 |
| advancemame | advancecomp | >= 0 < 2.1-2.1ubuntu2.1 | 2.1-2.1ubuntu2.1 |
| advancemame | advancecomp | >= 0 < 1.20-1ubuntu0.2+esm2 | 1.20-1ubuntu0.2+esm2 |
| debian | advancecomp | < advancecomp 2.4-1 (bookworm) | advancecomp 2.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
advancecomp vulnerabilities
osv·2023-02-01·CVSS 5.5
CVE-2022-35014 [MEDIUM] advancecomp vulnerabilities
advancecomp vulnerabilities
It was discovered that AdvanceCOMP did not properly manage memory while
performing read operations on MNG file. If a user were tricked into opening
a specially crafted MNG file, a remote attacker could possibly use this
issue to cause AdvanceCOMP to crash, resulting in a denial of service.
(CVE-2022-35014, CVE-2022-35017, CVE-2022-35018, CVE-2022-35019,
CVE-2022-35020)
It was discovered that AdvanceCOMP did not properly manage memory while
performing read operations on ZIP file. If a user were tricked into opening
a specially crafted ZIP file, a remote attacker could possibly use this
issue to cause AdvanceCOMP to crash, resulting in a denial of service.
(CVE-2022-35015, CVE-2022-35016)
GHSA
GHSA-jrvp-mrj4-gx7v: Advancecomp v2
ghsa_unreviewed·2022-08-29
CVE-2022-35019 [MEDIUM] GHSA-jrvp-mrj4-gx7v: Advancecomp v2
Advancecomp v2.3 was discovered to contain a segmentation fault.
OSV
CVE-2022-35019: Advancecomp v2
osv·2022-08-29·CVSS 5.5
CVE-2022-35019 [MEDIUM] CVE-2022-35019: Advancecomp v2
Advancecomp v2.3 was discovered to contain a segmentation fault.
Ubuntu
AdvanceCOMP vulnerabilities
vendor_ubuntu·2023-02-01·CVSS 5.5
CVE-2022-35016 [MEDIUM] AdvanceCOMP vulnerabilities
Title: AdvanceCOMP vulnerabilities
Summary: Several security issues were fixed in AdvanceCOMP.
It was discovered that AdvanceCOMP did not properly manage memory while
performing read operations on MNG file. If a user were tricked into opening
a specially crafted MNG file, a remote attacker could possibly use this
issue to cause AdvanceCOMP to crash, resulting in a denial of service.
(CVE-2022-35014, CVE-2022-35017, CVE-2022-35018, CVE-2022-35019,
CVE-2022-35020)
It was discovered that AdvanceCOMP did not properly manage memory while
performing read operations on ZIP file. If a user were tricked into opening
a specially crafted ZIP file, a remote attacker could possibly use this
issue to cause AdvanceCOMP to crash, resulting in a denial of service.
(CVE-2022-35015, CVE-2022-35016)
Instr
Red Hat
advancecomp: SEGV via invalid write memory access
vendor_redhat·2022-08-29·CVSS 5.5
CVE-2022-35019 [MEDIUM] CWE-119 advancecomp: SEGV via invalid write memory access
advancecomp: SEGV via invalid write memory access
Advancecomp v2.3 was discovered to contain a segmentation fault.
A segmentation fault was found in advancecomp in the mng_read_delta() function of the mng.c file. The flaw occurs due to invalid WRITE memory access. This flaw allows an attacker to cause a crash by tricking a user into opening a malformed file, leading to a denial of service attack.
Package: advancecomp (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2022-35019: advancecomp - Advancecomp v2.3 was discovered to contain a segmentation fault.
vendor_debian·2022·CVSS 5.5
CVE-2022-35019 [MEDIUM] CVE-2022-35019: advancecomp - Advancecomp v2.3 was discovered to contain a segmentation fault.
Advancecomp v2.3 was discovered to contain a segmentation fault.
Scope: local
bookworm: resolved (fixed in 2.4-1)
bullseye: open
forky: resolved (fixed in 2.4-1)
sid: resolved (fixed in 2.4-1)
trixie: resolved (fixed in 2.4-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://drive.google.com/file/d/1n1hltvw-kqpzZ50L6d7RGGNagwbUp0Z2/view?usp=sharinghttps://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35019.mdhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYG2XAL4MBS7ADGJWYRUKBLDTBJFPJER/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQHLMLFHPV5C7PTBZML6U72QT6VNEOEF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XP42AC5VPTY45QKMRL3W4G4EXIUMFXRE/https://drive.google.com/file/d/1n1hltvw-kqpzZ50L6d7RGGNagwbUp0Z2/view?usp=sharinghttps://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35019.mdhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYG2XAL4MBS7ADGJWYRUKBLDTBJFPJER/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQHLMLFHPV5C7PTBZML6U72QT6VNEOEF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XP42AC5VPTY45QKMRL3W4G4EXIUMFXRE/
2022-08-29
Published