CVE-2018-1056
Summary
| CVE | CVE-2018-1056 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-27 18:29:00 UTC |
| Updated | 2022-01-21 14:47:00 UTC |
| Description | An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| USN-3570-1: AdvanceCOMP vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| 1542333 – (CVE-2018-1056) CVE-2018-1056 advancecomp: Heap buffer overflow in zip.cc:zip_entry::load_cent() allows for denial of service or unspecified impact via crafted ZIP file |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 1702-1] advancecomp security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 2868-1] advancecomp security update |
MLIST |
lists.debian.org |
|
| #889270 - advancecomp: CVE-2018-1056: heap buffer overflow while running advzip - Debian Bug report logs |
CONFIRM |
bugs.debian.org |
Exploit, Issue Tracking, Third Party Advisory |
| AdvanceMAME / Bugs / #259 CVE-2018-1056: heap buffer overflow while running advzip |
CONFIRM |
sourceforge.net |
Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 1281-1] advancecomp security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178973 Debian Security Update for advancecomp (DLA 2868-1)
- 690379 Free Berkeley Software Distribution (FreeBSD) Security Update for advancecomp (0bf816f6-3cfe-11ec-86cd-dca632b19f10)