In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2019-02-27 14:29
Updated : 2024-11-21 04:51
NVD link : CVE-2019-9210
Mitre link : CVE-2019-9210
CVE.ORG link : CVE-2019-9210
JSON object : View
Products Affected
canonical
- ubuntu_linux
fedoraproject
- fedora
advancemame
- advancecomp
debian
- debian_linux