CVE-2019-14296Improper Restriction of Operations within the Bounds of a Memory Buffer in Upx-ucl

Severity
7.8HIGHNVD
EPSS
0.5%
top 35.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 27
Latest updateMay 24

Description

canUnpack in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (SEGV or buffer overflow, and application crash) or possibly have unspecified other impact via a crafted UPX packed file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

debiandebian/upx-ucl< upx-ucl 3.95-2 (bullseye)
NVDupx/upx3.95

Patches

🔴Vulnerability Details

2
GHSA
GHSA-528r-q74g-hxwp: canUnpack in p_vmlinx2022-05-24
OSV
CVE-2019-14296: canUnpack in p_vmlinx2019-07-27

📋Vendor Advisories

1
Debian
CVE-2019-14296: upx-ucl - canUnpack in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial ...2019

💬Community

4
Bugzilla
CVE-2019-14296 upx: denial of service in canUnpack in p_vmlinx.cpp2019-08-01
Bugzilla
CVE-2019-14296 upx: denial of service in canUnpack in p_vmlinx.cpp [fedora-all]2019-08-01
Bugzilla
CVE-2019-14296 upx: denial of service in canUnpack in p_vmlinx.cpp [epel-7]2019-08-01
Bugzilla
CVE-2019-12802 radare2: denial of service in function rcc_context in /libr/egg/egg_lang.c2019-06-21
CVE-2019-14296 — Debian Upx-ucl vulnerability | cvebase