Menu

#298 CVE-2022-35015 advancecomp: heap-buffer-overflow in le_uint32_read() in lib/endianrw.h

other
closed-fixed
nobody
None
5
2022-11-23
2022-11-22
Ben Beasley
No

Advancecomp v2.3 was discovered to contain a heap buffer overflow via le_uint32_read at /lib/endianrw.h.

https://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35015.md
https://drive.google.com/file/d/1pxNOlyl5mWXdVwkmCD4ZuXEPxI3PZAac/view?usp=sharing

This was reported downstream in Fedora Linux and Fedora EPEL, where I’m the current maintainer of the advancecomp package.

Discussion

  • Andrea Mazzoleni

    • status: open --> closed-fixed
     
  • Andrea Mazzoleni

    Fixed in github with commit "Check for truncated end of central directory"

     
  • Ben Beasley

    Ben Beasley - 2022-11-23
    Post awaiting moderation.

Log in to post a comment.