CVE-2021-43317: Buffer Overflow
Published Mar 24, 2023
·Updated
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func getle32(). The problem is essentially caused in PackLinuxElf64::elflookup() at plxelf.cpp:5404
Affected Software
1 affected component
Upx Project Upx<4.0.0
Remediation
Patch Available
Event History
Mar 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-43317.
2
What is the severity of CVE-2021-43317?
The severity of CVE-2021-43317 is high, with a severity value of 7.5.
3
Which software is affected by CVE-2021-43317?
The software affected by CVE-2021-43317 is Upx Project Upx up to version 4.0.0.
4
What is the CWE ID associated with CVE-2021-43317?
The CWE ID associated with CVE-2021-43317 is CWE-119 and CWE-787.
5
Is there a reference for CVE-2021-43317?
Yes, you can find more information about CVE-2021-43317 at this reference: https://github.com/upx/upx/issues/380