PT-2021-13877 · Upx+1 · Upx+1

Hustcw

·

Published

2021-03-26

·

Updated

2025-04-11

·

CVE-2021-20285

CVSS v2.0

8.3

High

VectorAV:N/AC:M/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions: UPX version 3.96
Description: A flaw was found in upx canPack in p lx elf.cpp. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from this vulnerability is to system availability.
Recommendations: For UPX version 3.96, consider updating to a newer version that contains a fix for this issue, as the current version is affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2021-20285
MGASA-2021-0241
OPENSUSE-SU-2023:0088-1

Affected Products

Debian
Upx