CVE-2020-27790: Divide by Zero
Published Aug 18, 2022
·Updated
A floating point exception issue was discovered in UPX in PackLinuxElf64::invertptdynamic() function of plxelf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service. The highest impact is to Availability.
Affected Software
1 affected component
Upx Project Upx<3.96
Remediation
Patch Available
Event History
Aug 18, 2022
CVE Published
via MITRE·06:57 PM
Data Sourced
via MITRE·06:57 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-27790.
2
What is the title of the vulnerability?
The title of the vulnerability is 'A floating point exception issue in UPX in PackLinuxElf64::invert_pt_dynamic() function.'
3
What is the impact of CVE-2020-27790?
The highest impact of CVE-2020-27790 is to Availability.
4
How can CVE-2020-27790 be triggered?
CVE-2020-27790 can be triggered by an attacker with a crafted input file.
5
How can CVE-2020-27790 be fixed?
To fix CVE-2020-27790, update UPX to version 3.96 or later.