CVE-2022-35020: Buffer Overflow
Advancecomp v2.3 was discovered to contain a heap buffer overflow via the component interceptormemcpy at /sanitizercommon/sanitizercommoninterceptors.inc.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35020?
CVE-2022-35020 is a vulnerability in Advancecomp v2.3 that allows a heap buffer overflow via the component __interceptor_memcpy.
What is the severity of CVE-2022-35020?
CVE-2022-35020 has a severity level of medium with a CVSS score of 5.5.
Which software versions are affected by CVE-2022-35020?
Advancecomp v2.3, Fedora 35, Fedora 36, and Fedora 37 are affected by CVE-2022-35020.
How can I fix CVE-2022-35020?
To fix CVE-2022-35020, it is recommended to update to a patched version of Advancecomp or apply the necessary security patches provided by the software vendor.
Where can I find more information about CVE-2022-35020?
You can find more information about CVE-2022-35020 in the references provided: [Reference 1](https://drive.google.com/file/d/1ScTmAEmHSHvmyDnELYV1DzQTAAAm7XS9/view?usp=sharing), [Reference 2](https://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35020.md), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DYG2XAL4MBS7ADGJWYRUKBLDTBJFPJER/)