CVE-2022-35015 advancecomp: heap-buffer-overflow in le_uint32_read() in...
Brought to you by:
amadvance
Advancecomp v2.3 was discovered to contain a heap buffer overflow via le_uint32_read at /lib/endianrw.h.
https://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35015.md
https://drive.google.com/file/d/1pxNOlyl5mWXdVwkmCD4ZuXEPxI3PZAac/view?usp=sharing
This was reported downstream in Fedora Linux and Fedora EPEL, where I’m the current maintainer of the advancecomp package.
Fixed in github with commit "Check for truncated end of central directory"