CVE-2020-27799: Buffer Overflow
Published Aug 25, 2022
·Updated
A heap-based buffer over-read was discovered in the accuagetbe32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.
Affected Software
1 affected component
Upx Project Upx=4.0.0
Event History
Aug 25, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-27799?
CVE-2020-27799 is a heap-based buffer over-read vulnerability in UPX version 4.0.0.
2
How does the CVE-2020-27799 vulnerability occur?
CVE-2020-27799 occurs due to a heap-based buffer over-read in the acc_ua_get_be32 function in miniacc.h in UPX.
3
What is the severity of CVE-2020-27799?
CVE-2020-27799 has a severity of 7.8 (high).
4
What software versions are affected by CVE-2020-27799?
UPX version 4.0.0 is affected by CVE-2020-27799.
5
How can I fix CVE-2020-27799?
There is currently no known fix or patch for CVE-2020-27799. It is recommended to update to the latest version of UPX when a patch becomes available.