CVE-2021-20285: Buffer Overflow
A flaw was found in upx canPack in plxelf.cpp in UPX 3.96 that allows attackers to cause a denial of service (SEGV or buffer overflow, and application crash) or possibly have unspecified other impacts via a crafted ELF.
Upstream issue:
https://github.com/upx/upx/issues/421
Other sources
A flaw was found in upx canPack in plxelf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from this vulnerability is to system availability.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20285?
CVE-2021-20285 is a vulnerability found in UPX 3.96 that allows attackers to cause a denial of service or potentially have unspecified impacts via a crafted ELF file.
What is the severity of CVE-2021-20285?
The severity of CVE-2021-20285 is high, with a CVSS score of 6.6.
How does CVE-2021-20285 impact system availability?
CVE-2021-20285 can cause a denial of service (SEGV or buffer overflow and application crash), posing a threat to system availability.
What version of UPX is affected by CVE-2021-20285?
UPX version 3.96 is affected by CVE-2021-20285.
Are there any references available for CVE-2021-20285?
Yes, you can find references for CVE-2021-20285 at the following links: [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1937787) and [GitHub](https://github.com/upx/upx/issues/421).