First published: Thu Aug 25 2022(Updated: )
A heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
UPX | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2020-27796.
The severity of CVE-2020-27796 is high with a score of 7.8.
The affected software is UPX version 4.0.0.
The vulnerability occurs due to a heap-based buffer over-read in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
Yes, the UPX project has addressed the vulnerability in newer versions. It is recommended to update to the latest version of UPX to fix CVE-2020-27796.