PT-2023-12434 · Upx+1 · Upx+1

Published

2023-03-24

·

Updated

2023-10-22

·

CVE-2021-43317

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions upx (affected versions not specified)
Description A heap-based buffer overflow was discovered in the upx software. The issue arises when the generic pointer 'p' points to an inaccessible address in the get le32() function. This problem is essentially caused by the PackLinuxElf64::elf lookup() function at p lx elf.cpp:5404.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2021-43317
OPENSUSE-SU-2023:0088-1
ROSA-SA-2023-2260

Affected Products

Debian
Upx