CVE-2022-35014 advancecomp: SEGV via invalid read address
Brought to you by:
amadvance
Advancecomp v2.3 contains a segmentation fault.
https://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35014.md
https://drive.google.com/file/d/1mglfof2gR9Xoi5OWS9x0-jJ7cSIJA5i6/view?usp=sharing
This was reported downstream in Fedora Linux and Fedora EPEL, where I’m the current maintainer of the advancecomp package.
Fixed in github with commit "Fix not initialized pointer"