Lucene search

K
freebsdFreeBSDB6A84729-6BD0-11ED-8D9A-B42E991FC52E
HistoryAug 29, 2022 - 12:00 a.m.

advancecomp -- Multiple vulnerabilities

2022-08-2900:00:00
vuxml.freebsd.org
11
github advisories
segmentation faults
heap buffer overflow
endianrw.h

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

47.4%

GitHub advisories reports:

Multiple vulnerabilities found in advancecomp including:

Three segmentation faults.
Heap buffer overflow via le_uint32_read at /lib/endianrw.h.
Three more heap buffer overflows.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchadvancecomp< 2.4UNKNOWN

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

47.4%