CVE-2020-27788: Medium severity upx vulnerability
Published Aug 18, 2022
·Updated
An out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of plxelf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service.
Affected Software
1 affected component
Upx Project Upx<3.96
Remediation
Patch Available
Event History
Aug 18, 2022
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-27788?
CVE-2020-27788 is an out-of-bounds read access vulnerability in UPX.
2
What software is affected by CVE-2020-27788?
UPX versions up to but not including 3.96 are affected by CVE-2020-27788.
3
What is the severity of CVE-2020-27788?
The severity of CVE-2020-27788 is medium with a score of 5.5.
4
How can an attacker exploit CVE-2020-27788?
An attacker with a crafted input file can trigger CVE-2020-27788.
5
Is there a fix for CVE-2020-27788?
Yes, the issue has been addressed in UPX commit 1bb93d4fce9f1d764ba57bf5ac154af515b3fc83.