CVE-2019-9210: Integer Overflow
In AdvanceCOMP 2.1, pngcompress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-9210?
CVE-2019-9210 is a vulnerability in AdvanceCOMP 2.1 that results in an integer overflow and a heap-based buffer over-read.
What is the severity of CVE-2019-9210?
CVE-2019-9210 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2019-9210?
AdvanceCOMP versions 2.1, 2.5-1, and certain Ubuntu and Debian packages are affected by CVE-2019-9210.
How can I fix CVE-2019-9210?
To fix CVE-2019-9210, update AdvanceCOMP to version 2.1-2.1 or 2.5-1, or apply the respective remedies provided by Debian and Ubuntu.
Where can I find more information about CVE-2019-9210?
More information about CVE-2019-9210 can be found in the references provided: [link1], [link2], [link3].