Advancecomp v2.3 was discovered to contain a heap buffer overflow via le_uint32_read at /lib/endianrw.h. https://github.com/Cvjark/Poc/blob/main/advancecomp/CVE-2022-35015.md https://drive.google.com/file/d/1pxNOlyl5mWXdVwkmCD4ZuXEPxI3PZAac/view?usp=sharing
Created advancecomp tracking bugs for this issue: Affects: epel-all [bug 2127382] Affects: fedora-all [bug 2127381]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-35015