PT-2026-102637 · Ncompress · Ncompress
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
compress versions prior to 1.18.7
Description
A signed integer overflow occurs in the
s2.NewDict() function when a dictionary is supplied with a uvarint-encoded repeat value that exceeds MaxInt64. This allows an attacker to bypass repeat index validation. Subsequently, calling the Dict.Encode() function results in an out-of-bounds memory access via unsafe.Pointer arithmetic, leading to a process crash with SIGSEGV (a segmentation fault, which occurs when a program attempts to access a memory location it is not allowed to access).Recommendations
Update to version 1.18.7.
Exploit
Fix
Memory Corruption
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ncompress