REDHAT-BUG-2160382: Medium severity upx upx vulnerability
A Segmentation fault was found in UPX in invertptdynamic() function in plxelf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.
https://github.com/upx/upx/issues/631 https://github.com/upx/upx/commit/779b648c5f6aa9b33f4728f79dd4d0efec0bf860
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2160382?
The severity of REDHAT-BUG-2160382 is classified as critical due to the potential for denial of service caused by a segmentation fault.
How do I fix REDHAT-BUG-2160382?
To fix REDHAT-BUG-2160382, upgrade to the latest patched version of UPX or apply the recommended security fixes.
What causes the vulnerability identified as REDHAT-BUG-2160382?
REDHAT-BUG-2160382 is caused by a segmentation fault in the invert_pt_dynamic() function, which allows attackers to exploit invalid memory address access.
What is the impact of exploiting REDHAT-BUG-2160382?
Exploiting REDHAT-BUG-2160382 can lead to a denial of service by crashing the application handling malicious input.
Which versions of UPX are affected by REDHAT-BUG-2160382?
UPX is affected by REDHAT-BUG-2160382 across all versions until the vulnerability is patched.