CVE-2022-35017 advancecomp: heap-buffer-overflow in mng_delta_addition() in mng.c
Brought to you by:
amadvance
Advancecomp v2.3 was discovered to contain a heap buffer overflow.
https://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35017.md
https://drive.google.com/file/d/13WAtJtCUBH4LW5MBulyuhLFq2HQq4e_Q/view?usp=sharing
This was reported downstream in Fedora Linux and Fedora EPEL, where I’m the current maintainer of the advancecomp package.
Fixed in github with commit "Check move chunk"
Thank you for the quick investigation and fix.