First published: Wed Feb 14 2018(Updated: )
Joonun Jang discovered that AdvanceCOMP incorrectly handled certain malformed zip files. If a user or automated system were tricked into processing a specially crafted zip file, a remote attacker could cause AdvanceCOMP to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/advancecomp | <2.0-1ubuntu0.1 | 2.0-1ubuntu0.1 |
Ubuntu Ubuntu | =17.10 | |
All of | ||
ubuntu/advancecomp | <1.20-1ubuntu0.1 | 1.20-1ubuntu0.1 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/advancecomp | <1.18-1ubuntu0.1 | 1.18-1ubuntu0.1 |
Ubuntu Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this AdvanceCOMP vulnerability is USN-3570-1.
The AdvanceCOMP version 2.0-1ubuntu0.1 on Ubuntu 17.10, version 1.20-1ubuntu0.1 on Ubuntu 16.04, and version 1.18-1ubuntu0.1 on Ubuntu 14.04 are affected by this vulnerability.
Exploiting this vulnerability can cause AdvanceCOMP to crash, resulting in a denial of service, or possibly execute arbitrary code.
To fix this vulnerability, you should update the AdvanceCOMP package to the specified remedial version for your Ubuntu distribution.
You can find more information about this vulnerability on the Ubuntu Security Notice page and the Ubuntu Launchpad for the AdvanceCOMP package.