CVE-2021-43312: Buffer Overflow
Published Mar 24, 2023
·Updated
A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf64::invertptdynamic at plxelf.cpp:5239.
Affected Software
1 affected component
Upx Project Upx<4.0.0
Remediation
Patch Available
Event History
Mar 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43312.
2
What is the severity of CVE-2021-43312?
The severity of CVE-2021-43312 is high, with a severity score of 7.5.
3
Which software is affected by CVE-2021-43312?
The software affected by CVE-2021-43312 is Upx Project Upx, version up to 4.0.0.
4
What is the description of CVE-2021-43312?
CVE-2021-43312 is a heap-based buffer overflow vulnerability discovered in upx, which triggers an issue in the PackLinuxElf64::invert_pt_dynamic function.
5
Where can I find more information about CVE-2021-43312?
You can find more information about CVE-2021-43312 at the following reference link: https://github.com/upx/upx/issues/379