CVE-2020-27801: Buffer Overflow
Published Aug 25, 2022
·Updated
A heap-based buffer over-read was discovered in the getle64 function in bele.h in UPX 4.0.0 via a crafted Mach-O file.
Affected Software
1 affected component
Upx Project Upx=4.0.0
Event History
Aug 25, 2022
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-27801?
CVE-2020-27801 is a vulnerability in UPX 4.0.0 that allows a heap-based buffer over-read via a crafted Mach-O file.
2
How severe is CVE-2020-27801?
CVE-2020-27801 has a severity rating of 7.8 (high).
3
How does CVE-2020-27801 affect UPX?
CVE-2020-27801 affects UPX version 4.0.0.
4
How can I fix the vulnerability?
Currently, there is no known fix for CVE-2020-27801. It is recommended to update to a patched version of UPX when it becomes available.
5
Where can I find more information about CVE-2020-27801?
More information about CVE-2020-27801 can be found at the following reference: [https://github.com/upx/upx/issues/394](https://github.com/upx/upx/issues/394)