CVE-2019-14296: Buffer Overflow
Published Jul 27, 2019
·Updated
canUnpack in pvmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (SEGV or buffer overflow, and application crash) or possibly have unspecified other impact via a crafted UPX packed file.
Affected Software
1 affected component
Upx Project Upx=3.95
Remediation
Patch Available
Event History
Jul 27, 2019
CVE Published
via MITRE·06:40 PM
Data Sourced
via MITRE·06:40 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this UPX vulnerability?
The vulnerability ID of this UPX vulnerability is CVE-2019-14296.
2
What is the severity of CVE-2019-14296?
The severity of CVE-2019-14296 is high.
3
What is the affected version of UPX?
The affected version of UPX is 3.95.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted UPX packed file.
5
Are there any references related to this vulnerability?
Yes, you can find references related to this vulnerability at the following links: [link 1], [link 2], [link 3].