CVE-2018-1056: High severity AdvanceMAME AdvanceCOMP vulnerability
An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-1056?
CVE-2018-1056 is an out-of-bounds heap buffer read flaw found in the advancecomp package.
How does CVE-2018-1056 affect advancecomp?
CVE-2018-1056 could potentially crash the advzip utility if it processes manipulated ZIP files.
What is the severity of CVE-2018-1056?
CVE-2018-1056 has a severity value of 7.8, which is considered high.
How can I fix CVE-2018-1056?
To fix CVE-2018-1056, update to advancecomp version 2.1-2018/02 or later.
Where can I find more information about CVE-2018-1056?
You can find more information about CVE-2018-1056 at the following references: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1056), [Debian Bug Report](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889270), [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2018/02/msg00016.html).