CVE-2020-27796: Buffer Overflow
Published Aug 25, 2022
·Updated
A heap-based buffer over-read was discovered in the invertptdynamic function in plxelf.cpp in UPX 4.0.0 via a crafted Mach-O file.
Affected Software
1 affected component
Upx Project Upx=4.0.0
Event History
Aug 25, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-27796.
2
What is the severity of CVE-2020-27796?
The severity of CVE-2020-27796 is high with a score of 7.8.
3
What is the affected software?
The affected software is UPX version 4.0.0.
4
How does the vulnerability occur?
The vulnerability occurs due to a heap-based buffer over-read in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file.
5
Is there a fix available for CVE-2020-27796?
Yes, the UPX project has addressed the vulnerability in newer versions. It is recommended to update to the latest version of UPX to fix CVE-2020-27796.