Security Vulnerabilities fixed in advancecomp RHSA-2019:2332

description-logoDescription

AdvanceCOMP is a set of recompression utilities for .PNG, .MNG and .ZIP files. Security Fix(es): * advancecomp: null pointer dereference in function be_uint32_read() in endianrw.h (CVE-2019-8379) * advancecomp: denial of service in function adv_png_unfilter_8 in lib/png.c (CVE-2019-8383) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.

affected-products-logoAffected Applications

advancecomp

CVE References

CVE-2019-8379 CVE-2019-8383