CVE-2021-43311: Buffer Overflow
Published Mar 24, 2023
·Updated
A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func getle32(). The problem is essentially caused in PackLinuxElf32::elflookup() at plxelf.cpp:5382.
Affected Software
1 affected component
Upx Project Upx<4.0.0
Remediation
Patch Available
Event History
Mar 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this heap-based buffer overflow in upx?
The vulnerability ID for this heap-based buffer overflow in upx is CVE-2021-43311.
2
What is the affected software by this vulnerability?
The affected software by this vulnerability is upx version up to 4.0.0.
3
What is the severity rating of CVE-2021-43311?
The severity rating of CVE-2021-43311 is high (7.5).
4
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-119 and CWE-787.
5
Is there a reference URL for more information about this vulnerability?
Yes, for more information about this vulnerability, you can refer to the GitHub issue: https://github.com/upx/upx/issues/380