First published: Sat Feb 03 2018(Updated: )
An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advancemame Advancecomp | <2.1 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
debian/advancecomp | <=2.0-1<=1.19-1 | |
debian/advancecomp | 2.1-2.1 2.5-1 | |
ubuntu/advancecomp | <2.0-1ubuntu0.1 | 2.0-1ubuntu0.1 |
ubuntu/advancecomp | <1.18-1ubuntu0.1 | 1.18-1ubuntu0.1 |
ubuntu/advancecomp | <2.1-1 | 2.1-1 |
ubuntu/advancecomp | <1.20-1ubuntu0.1 | 1.20-1ubuntu0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1056 is an out-of-bounds heap buffer read flaw found in the advancecomp package.
CVE-2018-1056 could potentially crash the advzip utility if it processes manipulated ZIP files.
CVE-2018-1056 has a severity value of 7.8, which is considered high.
To fix CVE-2018-1056, update to advancecomp version 2.1-2018/02 or later.
You can find more information about CVE-2018-1056 at the following references: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1056), [Debian Bug Report](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889270), [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2018/02/msg00016.html).