CVE-2020-24119Out-of-bounds Read in Upx-ucl

CWE-125Out-of-bounds Read4 documents4 sources
Severity
7.1HIGHNVD
EPSS
0.4%
top 39.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateMay 24

Description

A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

debiandebian/upx-ucl< upx-ucl 4.2.2-1 (forky)
NVDupx/upx4.0.0

Also affects: Fedora 33, 34

Patches

🔴Vulnerability Details

2
GHSA
GHSA-68mf-gv4w-rh82: A heap buffer overflow read was discovered in upx 42022-05-24
OSV
CVE-2020-24119: A heap buffer overflow read was discovered in upx 42021-05-14

📋Vendor Advisories

1
Debian
CVE-2020-24119: upx-ucl - A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_...2020
CVE-2020-24119 — Out-of-bounds Read in Debian Upx-ucl | cvebase