CVE-2021-43316: Buffer Overflow
Published Mar 24, 2023
·Updated
A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func getle64().
Affected Software
1 affected component
Upx Project Upx<4.0.0
Remediation
Patch Available
Event History
Mar 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-43316?
CVE-2021-43316 is a heap-based buffer overflow vulnerability discovered in the UPX software.
2
What is the severity of CVE-2021-43316?
CVE-2021-43316 has a severity rating of high (7.5).
3
Which software is affected by CVE-2021-43316?
The UPX software version 4.0.0 and earlier is affected by CVE-2021-43316.
4
How does the vulnerability manifest in UPX?
The vulnerability manifests as a heap-based buffer overflow when the 'p' pointer points to an inaccessible address in the function get_le64().
5
Is there a fix available for CVE-2021-43316?
At the moment, there is no fix available for CVE-2021-43316. Users are advised to follow the recommended mitigation measures.