advancecomp: null pointer dereference in function be_uint32_read() in endianrw.h
Published Feb 17, 2019
7.8
HIGHCVSS 3.1
EPSS 1.25%
Description
An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.
Affected products
No data.
Configuration 1
- < 2.1
Configuration 2
- 9.0
Configuration 3
- 35
Configuration 4
- 7.0
- 7.0
- 7.0
No data.
Red Hat Enterprise Linux 7
advancecomp-0:1.15-21.el7
Fixed · RHSA-2019:2332
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | advancecomp-0:1.15-21.el7 | Fixed | RHSA-2019:2332 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of advancecomp as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having a security impact of Low. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
References (9)
- https://access.redhat.com/errata/RHSA-2019:2332 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-8379 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1708561 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2021/12/msg00034.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J23C6QSTJMQ467KAI6QG54AE4MZRLPQV/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-8379
- https://research.loginsoft.com/bugs/null-pointer-dereference-vulnerability-in-the-function-be_uint32_read-advancecomp/ x_refsource_MISCExploitThird Party Advisory
- https://sourceforge.net/p/advancemame/bugs/271/ x_refsource_MISCExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-8379
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:2332 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-8379 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1708561 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2021/12/msg00034.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J23C6QSTJMQ467KAI6QG54AE4MZRLPQV/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-8379 | ||
| https://research.loginsoft.com/bugs/null-pointer-dereference-vulnerability-in-the-function-be_uint32_read-advancecomp/ | x_refsource_MISCExploitThird Party Advisory | |
| https://sourceforge.net/p/advancemame/bugs/271/ | x_refsource_MISCExploitThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-8379 |
Change history (0)
No recorded changes yet.