REDHAT-BUG-2160381: Medium severity upx upx vulnerability
Published Jan 12, 2023
·Updated
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.1. The flow allows attackers to cause a denial of service (abort) via a crafted file.
https://github.com/upx/upx/issues/632 https://github.com/upx/upx/commit/510505a85cbe45e51fbd470f1aa8b02157c429d4
Affected Software
1 affected component
UPX UPX
Event History
Jan 12, 2023
Data Sourced
via Red Hat·08:26 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2160381?
The severity of REDHAT-BUG-2160381 is categorized as a denial of service vulnerability.
2
How do I fix REDHAT-BUG-2160381?
To fix REDHAT-BUG-2160381, update to the latest version of UPX that addresses this issue.
3
What is the impact of REDHAT-BUG-2160381?
The impact of REDHAT-BUG-2160381 is that it can allow attackers to cause an assertion abort and disrupt service.
4
Who is affected by REDHAT-BUG-2160381?
Users of UPX version 4.0.1 are affected by REDHAT-BUG-2160381.
5
Is there a workaround for REDHAT-BUG-2160381?
Currently, there are no documented workarounds for REDHAT-BUG-2160381 other than upgrading to a secure version.