Bug 1209769 (CVE-2021-43315) - VUL-0: CVE-2021-43315: upx: Heap-based buffer overflows in PackLinuxElf32:elf_lookup() at p_lx_elf.cp
Summary: VUL-0: CVE-2021-43315: upx: Heap-based buffer overflows in PackLinuxElf32:elf...
Status: RESOLVED FIXED
Alias: CVE-2021-43315
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Jan Engelhardt
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/361183/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-03-27 07:31 UTC by Cathy Hu
Modified: 2024-06-07 13:59 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cathy Hu 2023-03-27 07:31:32 UTC
CVE-2021-43315

A heap-based buffer overflows was discovered in upx, during the generic pointer
'p' points to an inaccessible address in func get_le32(). The problem is
essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5349

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-43315
https://www.cve.org/CVERecord?id=CVE-2021-43315
https://github.com/upx/upx/issues/380
Comment 1 Cathy Hu 2023-03-27 07:31:47 UTC
Affected:
- openSUSE:Backports:SLE-15-SP4/upx  3.96 

Not Affected:
- openSUSE:Factory/upx               4.0.2
Comment 2 Swamp Workflow Management 2023-04-11 13:12:00 UTC
openSUSE-SU-2023:0088-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1183510,1184701,1184702,1207121,1207122,1209765,1209766,1209767,1209768,1209769,1209770,1209771
CVE References: CVE-2021-20285,CVE-2021-30500,CVE-2021-30501,CVE-2021-43311,CVE-2021-43312,CVE-2021-43313,CVE-2021-43314,CVE-2021-43315,CVE-2021-43316,CVE-2021-43317,CVE-2023-23456,CVE-2023-23457
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP4 (src):    upx-4.0.2-bp154.4.6.1
Comment 3 Camila Camargo de Matos 2024-06-07 13:59:31 UTC
As per a comment [0] in the upstream issue related to this vulnerability [1], the reported problem is not present in version 4.0.2 of upx (the fix for the issue is present in version 4.0.2).

All currently supported codestreams are at version 4.0.2 or higher, meaning they are not affected by this issue.

[0] https://github.com/upx/upx/issues/380#issuecomment-1511845513
[1] https://github.com/upx/upx/issues/380