CVE-2022-35020
Description
Advancecomp v2.3 contains a heap buffer overflow in __interceptor_memcpy, exploitable via crafted compressed files, risking memory corruption or arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Advancecomp v2.3 contains a heap buffer overflow in __interceptor_memcpy, exploitable via crafted compressed files, risking memory corruption or arbitrary code execution.
Vulnerability
Advancecomp version 2.3 is affected by a heap buffer overflow vulnerability. The flaw resides in the __interceptor_memcpy function within /sanitizer_common/sanitizer_common_interceptors.inc. When processing specially crafted compressed files, the program may copy data beyond the bounds of a heap buffer, leading to memory corruption. No specific preconditions beyond opening a malicious file are described in the available references [1], [2], [3].
Exploitation
The attacker must supply a crafted compressed file that, when processed by advancecomp v2.3, triggers an exploitable heap buffer overflow in the __interceptor_memcpy interceptor. Exact attack steps have not been detailed in the public references [1], [2], [3]; however, exploitation typically involves sending the malicious file to the target user or system for processing.
Impact
Successful exploitation could allow an attacker to corrupt adjacent heap memory, potentially leading to information disclosure, application crashes, or arbitrary code execution with the privileges of the user running advancecomp. The specific impact depends on the attacker's ability to control the overflow size and content [1], [2], [3].
Mitigation
No patched version has been announced in the available references [1], [2], [3]. Users are advised to watch for updates to Advancecomp and apply the fix when available. Fedora package announcements referencing this CVE indicate that the flaw is known, but no fix is publicly released yet [1], [2], [3]. As a workaround, avoid processing untrusted compressed files with advancecomp v2.3.
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQHLMLFHPV5C7PTBZML6U72QT6VNEOEF/
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XP42AC5VPTY45QKMRL3W4G4EXIUMFXRE/
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DYG2XAL4MBS7ADGJWYRUKBLDTBJFPJER/
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Advancecomp/Advancecompdescription
- Range: = 2.3
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
5- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DYG2XAL4MBS7ADGJWYRUKBLDTBJFPJER/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KQHLMLFHPV5C7PTBZML6U72QT6VNEOEF/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XP42AC5VPTY45QKMRL3W4G4EXIUMFXRE/mitrevendor-advisory
- drive.google.com/file/d/1ScTmAEmHSHvmyDnELYV1DzQTAAAm7XS9/viewmitre
- github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35020.mdmitre
News mentions
0No linked articles in our index yet.