CVE-2021-43313: Buffer Overflow
Published Mar 24, 2023
·Updated
A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf32::invertptdynamic at plxelf.cpp:1688.
Affected Software
1 affected component
Upx Project Upx<4.0.0
Remediation
Patch Available
Event History
Mar 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this heap-based buffer overflow?
The vulnerability ID for this heap-based buffer overflow is CVE-2021-43313.
2
What is the affected software?
The affected software is Upx Project Upx version up to 4.0.0.
3
How severe is this vulnerability?
This vulnerability has a severity rating of 7.5 (high).
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-119, CWE-787.
5
Is there a reference for this vulnerability?
Yes, you can find the reference for this vulnerability at https://github.com/upx/upx/issues/378.