7.8
CVSSv3

CVE-2019-9210

Published: 27/02/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

It exists that AdvanceCOMP incorrectly handled certain PNG files. An attacker could possibly use this issue to execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

advancemame advancecomp 2.1

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

canonical ubuntu linux 19.04

fedoraproject fedora 30

Vendor Advisories

Debian Bug report logs - #923416 advancecomp: CVE-2019-9210 Package: src:advancecomp; Maintainer for src:advancecomp is Piotr Ożarowski <piotr@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 27 Feb 2019 21:09:01 UTC Severity: grave Tags: fixed-upstream, patch, security, upstream Found ...
AdvanceCOMP could be made to run arbitrary code if it opened a specially crafted file ...
AdvanceCOMP could be made to run arbitrary code if it opened a specially crafted file ...
In AdvanceCOMP 21, png_compress in pngexcc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small (There is also a heap-based buffer over-read) (CVE-2019-9210) ...
Impact: Moderate Public Date: 2019-02-27 CWE: CWE-190 Bugzilla: 1684596: CVE-2019-9210 advancecomp: int ...