CVE-2023-23456: Upx: heap-buffer-overflow in packtmt::pack()
A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in ptmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.
Other sources
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.1. The flow allows attackers to cause a denial of service (abort) via a crafted file.
https://github.com/upx/upx/issues/632 https://github.com/upx/upx/commit/510505a85cbe45e51fbd470f1aa8b02157c429d4
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-23456?
CVE-2023-23456 is a heap-based buffer overflow vulnerability discovered in UPX in the PackTmt::pack() function in the p_tmt.cpp file.
What is the severity of CVE-2023-23456?
The severity of CVE-2023-23456 is medium with a CVSS severity score of 5.5.
How does the vulnerability in CVE-2023-23456 impact users?
The vulnerability in CVE-2023-23456 allows an attacker to cause a denial of service (abort) by exploiting a heap-based buffer overflow issue in UPX.
What software versions are affected by CVE-2023-23456?
The affected software versions include UPX version up to exclusive 2022-11-24, and Fedora versions 36 and 37.
How can the vulnerability in CVE-2023-23456 be fixed?
To fix the vulnerability in CVE-2023-23456, users should update UPX to a version that includes the fix, or apply the necessary patches provided by the software vendor.