ALT-BU-2024-12063-1
Branch c10f1 update bulletin.
Package advancecomp updated to version 2.5-alt1_8 for branch c10f1 in task 356598.
Closed vulnerabilities
BDU:2020-02251
Уязвимость функции png_compress утилиты переупаковки архивов AdvanceCOMP, позволяющая нарушителю выполнить произвольный код
Modified: 2024-11-21
CVE-2019-8383
An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted file.
- RHSA-2019:2332
- [debian-lts-announce] 20211229 [SECURITY] [DLA 2868-1] advancecomp security update
- FEDORA-2019-b30b48200c
- https://research.loginsoft.com/bugs/invalid-memory-access-in-adv_png_unfilter_8-advancecomp/
- https://sourceforge.net/p/advancemame/bugs/272/
- RHSA-2019:2332
- https://sourceforge.net/p/advancemame/bugs/272/
- https://research.loginsoft.com/bugs/invalid-memory-access-in-adv_png_unfilter_8-advancecomp/
- FEDORA-2019-b30b48200c
- [debian-lts-announce] 20211229 [SECURITY] [DLA 2868-1] advancecomp security update
Modified: 2024-11-21
CVE-2019-9210
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)
- [debian-lts-announce] 20190302 [SECURITY] [DLA 1702-1] advancecomp security update
- [debian-lts-announce] 20211229 [SECURITY] [DLA 2868-1] advancecomp security update
- FEDORA-2019-ee98058a22
- https://sourceforge.net/p/advancemame/bugs/277/
- USN-3936-1
- USN-3936-2
- [debian-lts-announce] 20190302 [SECURITY] [DLA 1702-1] advancecomp security update
- USN-3936-2
- USN-3936-1
- https://sourceforge.net/p/advancemame/bugs/277/
- FEDORA-2019-ee98058a22
- [debian-lts-announce] 20211229 [SECURITY] [DLA 2868-1] advancecomp security update
Modified: 2025-01-08
CVE-2023-2961
A segmentation fault flaw was found in the Advancecomp package. This may lead to decreased availability.
Closed vulnerabilities
BDU:2024-05741
Уязвимость ядра веб-сервера Apache HTTP Server, позволяющая нарушителю раскрыть защищаемую информацию
Modified: 2025-03-14
CVE-2024-40725
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.