CVE-2020-27797: Buffer Overflow
Published Aug 25, 2022
·Updated
An invalid memory address reference was discovered in the elflookup function in plxelf.cpp in UPX 4.0.0 via a crafted Mach-O file.
Affected Software
1 affected component
Upx Project Upx=4.0.0
Event History
Aug 25, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-27797?
CVE-2020-27797 is a vulnerability in UPX 4.0.0 that allows for an invalid memory address reference in the elf_lookup function.
2
How does CVE-2020-27797 affect UPX?
CVE-2020-27797 affects UPX 4.0.0 by enabling a crafted Mach-O file to trigger an invalid memory address reference in the elf_lookup function.
3
What is the severity of CVE-2020-27797?
CVE-2020-27797 has a severity rating of medium with a score of 5.5.
4
How can I fix CVE-2020-27797 in UPX?
To fix CVE-2020-27797, it is recommended to update UPX to version 4.0.1 or later, as this vulnerability is addressed in the release.
5
Where can I find more information about CVE-2020-27797?
More information about CVE-2020-27797 can be found at the official GitHub repository for UPX, specifically in issue #390.