CVE-2019-20805: Integer Overflow
Published Jun 1, 2020
·Updated
plxelf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PTDYNAMIC segment.
Affected Software
1 affected component
Upx Project Upx<3.96
Remediation
Event History
Jun 1, 2020
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-20805.
2
What is the severity level of CVE-2019-20805?
CVE-2019-20805 has a severity level of 5.5 (medium).
3
Which software versions are affected by CVE-2019-20805?
Versions up to and excluding 3.96 of UPX are affected by CVE-2019-20805.
4
How can the integer overflow vulnerability be exploited?
The integer overflow vulnerability can be exploited during the unpacking process by providing crafted values in a PT_DYNAMIC segment.
5
Is there a fix available for CVE-2019-20805?
Yes, a fix for CVE-2019-20805 is available in UPX version 3.96 and later.