REDHAT-BUG-1937787: Buffer Overflow
A flaw was found in upx canPack in plxelf.cpp in UPX 3.96 that allows attackers to cause a denial of service (SEGV or buffer overflow, and application crash) or possibly have unspecified other impacts via a crafted ELF.
Upstream issue:
https://github.com/upx/upx/issues/421
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1937787?
The severity of REDHAT-BUG-1937787 is classified as critical due to the potential for denial of service and application crashes.
How do I fix REDHAT-BUG-1937787?
To fix REDHAT-BUG-1937787, upgrade to the latest version of UPX that addresses this vulnerability.
What type of attack is possible with REDHAT-BUG-1937787?
REDHAT-BUG-1937787 allows attackers to exploit a crafted ELF file to cause a denial of service or application crash.
What software is affected by REDHAT-BUG-1937787?
UPX version 3.96 is affected by the vulnerability identified in REDHAT-BUG-1937787.
Is there a workaround for REDHAT-BUG-1937787?
Currently, there are no official workarounds for REDHAT-BUG-1937787 aside from applying the necessary updates.