Medium severity5.3OSV Advisory· Published Jan 12, 2023· Updated Jun 17, 2026
CVE-2023-23456
CVE-2023-23456
Description
A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- osv-coords6 versionspkg:apk/chainguard/upxpkg:apk/chainguard/upx-docpkg:apk/wolfi/upxpkg:apk/wolfi/upx-docpkg:rpm/opensuse/upx&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/upx&distro=SUSE%20Package%20Hub%2015%20SP4
< 5.0.0-r0+ 5 more
- (no CPE)range: < 5.0.0-r0
- (no CPE)range: < 5.0.0-r0
- (no CPE)range: < 5.0.0-r0
- (no CPE)range: < 5.0.0-r0
- (no CPE)range: < 4.0.2-bp154.4.6.1
- (no CPE)range: < 4.0.2-bp154.4.6.1
Patches
Vulnerability mechanics
References
6- github.com/upx/upx/commit/510505a85cbe45e51fbd470f1aa8b02157c429d4nvdPatchThird Party Advisory
- github.com/upx/upx/issues/632nvdExploitThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2024/12/msg00013.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EL3BVKIGG3SH6I3KPOYQAWCBD4UMPOPI/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGEP3FBNRZXGLIA2B2ICMB32JVMPREFZ/nvd
News mentions
0No linked articles in our index yet.