First published: Fri Dec 27 2019(Updated: )
An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Upx Project Upx | =3.95 | |
Opensuse Backports | =sle-15-sp1 | |
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20053 is a vulnerability in the canUnpack function in UPX 3.95, which allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted Mach-O file.
CVE-2019-20053 affects UPX 3.95 and Opensuse Backports sle-15-sp1 and openSUSE Leap 15.1.
The severity of CVE-2019-20053 is medium, with a severity value of 5.5.
An attacker can exploit CVE-2019-20053 by sending a crafted Mach-O file to the vulnerable system, causing a denial of service or potentially executing arbitrary code.
Yes, fixes for CVE-2019-20053 are available. It is recommended to update UPX to a version that includes the fix.