PT-2019-13592 · Upx+1 · Upx+1

Aheroine

·

Publicado

2019-07-27

·

Atualizado

2025-04-11

·

CVE-2019-14295

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions UPX version 3.95
Description The issue is caused by an integer overflow in the getElfSections function, allowing remote attackers to trigger a denial of service by causing the program to crash. This is achieved by providing a skewed offset larger than the size of the PE section in a UPX packed executable, resulting in an allocation of excessive memory.
Recommendations For UPX version 3.95, consider updating to a newer version that addresses this issue, as the current version can lead to a denial of service due to excessive memory allocation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-2910
ALT-PU-2020-2930
CVE-2019-14295
MGASA-2020-0012

Produtos afetados

Alt Linux
Upx