CVE-2021-30501: Input Validation
Published Apr 12, 2021
·Updated
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.
Affected Software
3 affected components
Upx Project Upx=4.0.0
redhat Enterprise Linux=7.0
Fedoraproject Fedora=33
Remediation
Patch Available
Patch Available
Event History
Apr 12, 2021
Data Sourced
via Red Hat·06:40 PM
DescriptionSeverityAffected Software
May 26, 2021
CVE Published
via MITRE·11:54 PM
Data Sourced
via MITRE·11:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-30501?
The severity of CVE-2021-30501 is medium with a CVSS score of 5.5.
2
What is the affected software for CVE-2021-30501?
The affected software for CVE-2021-30501 includes Upx Project Upx version 4.0.0, Redhat Enterprise Linux version 7.0, and Fedoraproject Fedora version 33.
3
How can an attacker exploit CVE-2021-30501?
An attacker can cause a denial of service (abort) by exploiting the assertion abort in upx MemBuffer::alloc() in mem.cpp.
4
Is there a fix available for CVE-2021-30501?
Yes, a fix is available. It is recommended to update to a version of UPX that includes the fix.
5
Where can I find more information about CVE-2021-30501?
You can find more information about CVE-2021-30501 at the following references: [link1], [link2], [link3].