Bugzilla – Bug 1202550
VUL-1: CVE-2020-27788: upx: out-of-bounds read access vulnerability in PackLinuxElf64::canPack() function of p_lx_elf.cpp
Last modified: 2022-08-19 07:37:30 UTC
CVE-2020-27788 An out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-27788 https://github.com/upx/upx/commit/1bb93d4fce9f1d764ba57bf5ac154af515b3fc83 https://github.com/upx/upx/issues/332 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27788
Closing bug as already fixed. openSUSE:Backports:SLE-15-SP3:Update/upx 3.96 $ git tag --contains 1bb93d4fce9f1d764ba57bf5ac154af515b3fc83 v3.96