First published: Fri May 18 2018(Updated: )
PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
UPX | =3.95 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11243 is a vulnerability in UPX 3.95 that allows remote attackers to cause a denial of service (double free) or have other unspecified impact via a crafted file.
The severity of CVE-2018-11243 is high, with a severity value of 7.8.
CVE-2018-11243 affects UPX 3.95 and may limit the ability of a malware scanner to operate on the entire original data.
CVE-2018-11243 can be exploited by remote attackers through a crafted file.
Yes, fixes for CVE-2018-11243 have been released. It is recommended to update to the latest version of UPX (3.96 or later) to mitigate the vulnerability.