First published: Thu Mar 11 2021(Updated: )
A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96 that allows attackers to cause a denial of service (SEGV or buffer overflow, and application crash) or possibly have unspecified other impacts via a crafted ELF. Upstream issue: <a href="https://github.com/upx/upx/issues/421">https://github.com/upx/upx/issues/421</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
UPX | =3.96 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20285 is a vulnerability found in UPX 3.96 that allows attackers to cause a denial of service or potentially have unspecified impacts via a crafted ELF file.
The severity of CVE-2021-20285 is high, with a CVSS score of 6.6.
CVE-2021-20285 can cause a denial of service (SEGV or buffer overflow and application crash), posing a threat to system availability.
UPX version 3.96 is affected by CVE-2021-20285.
Yes, you can find references for CVE-2021-20285 at the following links: [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1937787) and [GitHub](https://github.com/upx/upx/issues/421).