7.8
CVE-2018-1056
- EPSS 1.42%
- Veröffentlicht 27.07.2018 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:59:04
- Erkennungen
An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Advancemame ≫ Advancecomp Version < 2.1
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 17.10
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.42% | 0.694 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
| RedHat | 3.3 | 1.8 | 1.4 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
|
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889270
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1056
https://lists.debian.org/debian-lts-announce/2018/02/msg00016.html
https://lists.debian.org/debian-lts-announce/2019/03/msg00004.html
https://lists.debian.org/debian-lts-announce/2021/12/msg00034.html
https://sourceforge.net/p/advancemame/bugs/259/
https://usn.ubuntu.com/3570-1/