Bugzilla – Bug 1202549
VUL-1: CVE-2020-27787: upx: segfault in invert_pt_dynamic() function in p_lx_elf.cpp
Last modified: 2022-08-19 07:37:33 UTC
CVE-2020-27787 A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-27787 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27787 https://github.com/upx/upx/commit/e2f60adc95334f47e286838dac33160819c5d74d https://github.com/upx/upx/issues/333
Closing bug as already fixed. openSUSE:Backports:SLE-15-SP3:Update/upx 3.96 $ git tag --contains e2f60adc95334f47e286838dac33160819c5d74d v3.96