CVE-2023-23457: Upx: segv on packlinuxelf64::invert_pt_dynamic() in p_lx_elf.cpp
A Segmentation fault was found in UPX in invertptdynamic() function in plxelf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.
https://github.com/upx/upx/issues/631 https://github.com/upx/upx/commit/779b648c5f6aa9b33f4728f79dd4d0efec0bf860
Other sources
A Segmentation fault was found in UPX in PackLinuxElf64::invertptdynamic() in plxelf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.
— NVD
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-23457.
What is the severity of CVE-2023-23457?
The severity of CVE-2023-23457 is medium (5.5).
Which software is affected by CVE-2023-23457?
The software affected by CVE-2023-23457 includes UPX (Upx Project Upx) versions before 2022-11-23 and Fedora versions 36 and 37 (Fedoraproject Fedora).
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by providing a crafted input file that allows invalid memory address access, leading to a denial of service.
Are there any references related to CVE-2023-23457?
Yes, you can find references related to CVE-2023-23457 at the following links: [Link 1](https://github.com/upx/upx/issues/631), [Link 2](https://github.com/upx/upx/commit/779b648c5f6aa9b33f4728f79dd4d0efec0bf860), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2160386).