CVE-2020-27800: Buffer Overflow
Published Aug 25, 2022
·Updated
A heap-based buffer over-read was discovered in the getle32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
Affected Software
1 affected component
Upx Project Upx=4.0.0
Event History
Aug 25, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-27800?
The severity of CVE-2020-27800 is high, with a severity value of 7.8.
2
How does CVE-2020-27800 affect UPX?
CVE-2020-27800 affects UPX version 4.0.0.
3
What is the CWE classification of CVE-2020-27800?
CVE-2020-27800 has two CWE classifications: CWE-125 (Out-of-bounds Read) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer).
4
Where can I find more information about CVE-2020-27800?
More information about CVE-2020-27800 can be found at the following link: [link](https://github.com/upx/upx/issues/395).
5
How can I fix the heap-based buffer over-read vulnerability in UPX 4.0.0?
To fix the heap-based buffer over-read vulnerability in UPX 4.0.0, it is recommended to update UPX to a version that has addressed this vulnerability.