REDHAT-BUG-1948696: Low severity upx upx vulnerability
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.
Upstream issue:
https://github.com/upx/upx/issues/486
Upstream patch: https://github.com/upx/upx/pull/487 https://github.com/upx/upx/commit/28e761cd42211dfe0124b7a29b2f74730f453e46
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1948696?
The severity of REDHAT-BUG-1948696 is classified as a denial of service vulnerability.
How do I fix REDHAT-BUG-1948696?
To fix REDHAT-BUG-1948696, you should apply the latest patch provided by the UPX maintainers.
What software is affected by REDHAT-BUG-1948696?
REDHAT-BUG-1948696 affects UPX version 4.0.0.
Can REDHAT-BUG-1948696 be exploited remotely?
Yes, REDHAT-BUG-1948696 can be exploited by attackers through crafted files.
What conditions lead to the vulnerability in REDHAT-BUG-1948696?
The vulnerability in REDHAT-BUG-1948696 is triggered by an assertion abort in the MemBuffer::alloc() function.