CVE-2018-11243: Double Free
PackLinuxElf64::unpack in plxelf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11243?
CVE-2018-11243 is a vulnerability in UPX 3.95 that allows remote attackers to cause a denial of service (double free) or have other unspecified impact via a crafted file.
What is the severity of CVE-2018-11243?
The severity of CVE-2018-11243 is high, with a severity value of 7.8.
How does CVE-2018-11243 affect UPX 3.95?
CVE-2018-11243 affects UPX 3.95 and may limit the ability of a malware scanner to operate on the entire original data.
How can CVE-2018-11243 be exploited?
CVE-2018-11243 can be exploited by remote attackers through a crafted file.
Is there a fix available for CVE-2018-11243?
Yes, fixes for CVE-2018-11243 have been released. It is recommended to update to the latest version of UPX (3.96 or later) to mitigate the vulnerability.