A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
2021-05-14T21:15:07.247
2025-04-11T12:27:55.013
Modified
CVSSv3.1: 7.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:N/A:P
8.6
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | upx | upx | 4.0.0 | Yes |
| Operating System | fedoraproject | fedora | 33 | Yes |
| Operating System | fedoraproject | fedora | 34 | Yes |