MEDIUM
advancecomp: heap-buffer-overflow in mng_delta_addition() in mng.c
Published Aug 29, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.47%
Description
Advancecomp v2.3 was discovered to contain a heap buffer overflow.
Affected products
No data.
Configuration 1
- 2.3
Configuration 2
OR
- 35
- 36
- 37
No data.
Red Hat Enterprise Linux 7
advancecomp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | advancecomp | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- https://access.redhat.com/security/cve/CVE-2022-35017 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2127383 Issue Tracking
- https://drive.google.com/file/d/13WAtJtCUBH4LW5MBulyuhLFq2HQq4e_Q/view?usp=sharing Broken LinkThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37915 Advisory
- https://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35017.md ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYG2XAL4MBS7ADGJWYRUKBLDTBJFPJER/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQHLMLFHPV5C7PTBZML6U72QT6VNEOEF/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XP42AC5VPTY45QKMRL3W4G4EXIUMFXRE/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-35017
- https://www.cve.org/CVERecord?id=CVE-2022-35017
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 29, 2022
Updated Aug 3, 2024
Reserved Jul 4, 2022
Link CVE-2022-35017
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-37915 Assigner mitre
Published Aug 29, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-37915