CVE-2020-27798: Buffer Overflow
Published Aug 25, 2022
·Updated
An invalid memory address reference was discovered in the adjABS function in plxelf.cpp in UPX 4.0.0 via a crafted Mach-O file.
Affected Software
1 affected component
Upx Project Upx=4.0.0
Event History
Aug 25, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-27798?
CVE-2020-27798 is a vulnerability discovered in UPX 4.0.0 that allows for an invalid memory address reference in the adjABS function.
2
How can a crafted Mach-O file exploit CVE-2020-27798?
A crafted Mach-O file can exploit CVE-2020-27798 by triggering the invalid memory address reference in the adjABS function of UPX 4.0.0.
3
What is the severity of CVE-2020-27798?
CVE-2020-27798 has a severity rating of medium with a CVSS score of 5.5.
4
What software versions are affected by CVE-2020-27798?
UPX 4.0.0 is affected by CVE-2020-27798.
5
Is there a fix available for CVE-2020-27798?
At the time of writing, there is no known fix available for CVE-2020-27798. It is recommended to update to a newer version of UPX when one becomes available.