CVE-2021-30500: Null Pointer Dereference
Null pointer dereference was found in upx PackLinuxElf::canUnpack() in plxelf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.
Upstream issue:
https://github.com/upx/upx/issues/48
Upstream patch:
https://github.com/upx/upx/commit/90279abdfcd235172eab99651043051188938dcc
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-30500.
What is the severity of CVE-2021-30500?
The severity of CVE-2021-30500 is high.
What is the affected software of CVE-2021-30500?
The affected software of CVE-2021-30500 includes UPX 4.0.0, Redhat Enterprise Linux 7.0, and Fedoraproject Fedora 33.
How can attackers exploit CVE-2021-30500?
Attackers can exploit CVE-2021-30500 by executing arbitrary code and causing a denial of service via a crafted file.
Are there any references available for CVE-2021-30500?
Yes, you can refer to the following links for more information: [Link 1](https://bugzilla.redhat.com/show_bug.cgi?id=1948692), [Link 2](https://github.com/upx/upx/commit/90279abdfcd235172eab99651043051188938dcc), [Link 3](https://github.com/upx/upx/issues/485).