Bugzilla – Bug 1202551
VUL-1: CVE-2020-27790: upx: floating point exception issue in PackLinuxElf64::invert_pt_dynamic() function of p_lx_elf.cpp
Last modified: 2022-08-19 07:37:28 UTC
CVE-2020-27790 A floating point exception issue was discovered in UPX in PackLinuxElf64::invert_pt_dynamic() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service. The highest impact is to Availability. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-27790 https://github.com/upx/upx/issues/331 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27790 https://github.com/upx/upx/commit/eb90eab6325d009004ffb155e3e33f22d4d3ca26
Closing bug as already fixed. openSUSE:Backports:SLE-15-SP3:Update/upx 3.96 $ git tag --contains eb90eab6325d009004ffb155e3e33f22d4d3ca26 v3.96