From 866e2e83cf2879600df62d4111c32333145b3f0c Mon Sep 17 00:00:00 2001 From: Robert Clausecker Date: Fri, 19 Nov 2021 04:47:50 -0500 Subject: security/vuxml: Document archivers/advancecomp vulnerabilities PR: 259534 --- security/vuxml/vuln-2021.xml | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/security/vuxml/vuln-2021.xml b/security/vuxml/vuln-2021.xml index ae2e7d778fb9..909c8fe96f1e 100644 --- a/security/vuxml/vuln-2021.xml +++ b/security/vuxml/vuln-2021.xml @@ -1,3 +1,36 @@ + + advancecomp -- multiple vulnerabilities + + + advancecomp + 2.1.6 + + + + +

Joonun Jang reports:

+
+

heap buffer overflow running advzip with "-l poc" option

+

Running 'advzip -l poc' with the attached file raises heap buffer overflow + which may allow a remote attacker to cause unspecified impact including denial-of-service attack. + I expected the program to terminate without segfault, but the program crashes as follow. [...] +

+
+

and other vulnerabilities.

+ +
+ + CVE-2018-1056 + CVE-2019-8379 + CVE-2019-8383 + CVE-2019-9210 + + + 2018-07-29 + 2021-11-19 + +
+ chromium -- multiple vulnerabilities -- cgit v1.2.3