advancecomp has been updated to fix a security issue that could be
triggered when pressented with a malformed PNG file. advancecomp
contained an integer overflow upon encountering an invalid PNG size, which
could result in a buffer overflow (CVE-2019-9210), as well as a heap-based
buffer over-read.
- https://bugs.mageia.org/show_bug.cgi?id=24535
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DPZCDOUS5QYMW45SCXCDPCWKC4QVMPLU/
- https://www.cve.org/CVERecord?id=CVE-2019-9210
- 6/core/advancecomp-1.20-3.3.mga6
Get the latest Linux and open source security news straight to your inbox.