High severity7.8OSV Advisory· Published Feb 27, 2019· Updated Jun 17, 2026
CVE-2019-9210
CVE-2019-9210
Description
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11advancecomp-1_10, advancecomp-1_11, advancecomp-1_12, …+ 1 more
- (no CPE)range: advancecomp-1_10, advancecomp-1_11, advancecomp-1_12, …
- cpe:2.3:a:advancemame:advancecomp:2.1:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- Range: <2.1
Patches
Vulnerability mechanics
References
6- sourceforge.net/p/advancemame/bugs/277/nvdExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/03/msg00004.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/12/msg00034.htmlnvdMailing ListThird Party Advisory
- usn.ubuntu.com/3936-1/nvdThird Party Advisory
- usn.ubuntu.com/3936-2/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R56LVWC7KUNXFRKQB3Y5NX2YHFJKYZB4/nvd
News mentions
0No linked articles in our index yet.