Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-23456

Опубликовано: 12 янв. 2023
Источник: debian

Описание

A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
upx-uclfixed4.2.2-1package
upx-uclno-dsabusterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2160381

  • https://github.com/upx/upx/commit/510505a85cbe45e51fbd470f1aa8b02157c429d4 (v4.0.2)

  • https://github.com/upx/upx/issues/632

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

CVSS3: 5.3
nvd
около 3 лет назад

A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

CVSS3: 5.5
github
около 3 лет назад

A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

suse-cvrf
почти 3 года назад

Security update for upx