First published: Thu Aug 18 2022(Updated: )
An out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
UPX | <3.96 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27788 is an out-of-bounds read access vulnerability in UPX.
UPX versions up to but not including 3.96 are affected by CVE-2020-27788.
The severity of CVE-2020-27788 is medium with a score of 5.5.
An attacker with a crafted input file can trigger CVE-2020-27788.
Yes, the issue has been addressed in UPX commit 1bb93d4fce9f1d764ba57bf5ac154af515b3fc83.