CVE-2022-35019 advancecomp: SEGV via invalid write memory access
Brought to you by:
amadvance
Advancecomp v2.3 was discovered to contain a segmentation fault.
https://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35019.md
https://drive.google.com/file/d/1n1hltvw-kqpzZ50L6d7RGGNagwbUp0Z2/view?usp=sharing
This was reported downstream in Fedora Linux and Fedora EPEL, where I’m the current maintainer of the advancecomp package.
Fixed in github with the commit "Check move chunk"
Thank you for the quick investigation and fix.