USN-3936-1: AdvanceCOMP vulnerability
Published Apr 4, 2019
·Updated
It was discovered that AdvanceCOMP incorrectly handled certain PNG files. An attacker could possibly use this issue to execute arbitrary code.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/advancecomp<2.1-1ubuntu0.18.10.1
2.1-1ubuntu0.18.10.1
Ubuntu Ubuntu=18.10
All of the following
ubuntu/advancecomp<2.1-1ubuntu0.18.04.1
2.1-1ubuntu0.18.04.1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/advancecomp<1.20-1ubuntu0.2
1.20-1ubuntu0.2
Ubuntu Ubuntu=16.04
All of the following
ubuntu/advancecomp<1.18-1ubuntu0.2
1.18-1ubuntu0.2
Ubuntu Ubuntu=14.04
Event History
Apr 4, 2019
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID of USN-3936-1?
The vulnerability ID of USN-3936-1 is CVE-2019-9210.
2
What is the severity of CVE-2019-9210?
The severity of CVE-2019-9210 is not specified.
3
What is AdvanceCOMP?
AdvanceCOMP is a compression utility for optimizing PNG files.
4
What is the affected version of AdvanceCOMP?
The affected version of AdvanceCOMP is 2.1-1ubuntu0.18.10.1, 2.1-1ubuntu0.18.04.1, 1.20-1ubuntu0.2, and 1.18-1ubuntu0.2.
5
How can the AdvanceCOMP vulnerability be exploited?
The AdvanceCOMP vulnerability can be exploited by an attacker to execute arbitrary code.