rpm package
suse/upx&distro=SUSE Package Hub 15 SP4
pkg:rpm/suse/upx&distro=SUSE%20Package%20Hub%2015%20SP4
Vulnerabilities (12)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-43317 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | Mar 24, 2023 | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf64::elf_lookup() at p_lx_elf.cpp:5404 | ||
| CVE-2021-43316 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | Mar 24, 2023 | A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64(). | ||
| CVE-2021-43315 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | Mar 24, 2023 | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5349 | ||
| CVE-2021-43314 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | Mar 24, 2023 | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5368 | ||
| CVE-2021-43313 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | Mar 24, 2023 | A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf32::invert_pt_dynamic at p_lx_elf.cpp:1688. | ||
| CVE-2021-43312 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | Mar 24, 2023 | A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf64::invert_pt_dynamic at p_lx_elf.cpp:5239. | ||
| CVE-2021-43311 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | Mar 24, 2023 | A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5382. | ||
| CVE-2023-23457 | — | < 4.0.1-bp154.4.3.1 | 4.0.1-bp154.4.3.1 | Jan 12, 2023 | A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service. | ||
| CVE-2023-23456 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | Jan 12, 2023 | A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file. | ||
| CVE-2021-30501 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | May 26, 2021 | An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file. | ||
| CVE-2021-30500 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | May 26, 2021 | Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file. | ||
| CVE-2021-20285 | — | < 4.0.2-bp154.4.6.1 | 4.0.2-bp154.4.6.1 | Mar 26, 2021 | A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from this vulnerability is to syst |
- CVE-2021-43317Mar 24, 2023affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf64::elf_lookup() at p_lx_elf.cpp:5404
- CVE-2021-43316Mar 24, 2023affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64().
- CVE-2021-43315Mar 24, 2023affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5349
- CVE-2021-43314Mar 24, 2023affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5368
- CVE-2021-43313Mar 24, 2023affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf32::invert_pt_dynamic at p_lx_elf.cpp:1688.
- CVE-2021-43312Mar 24, 2023affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf64::invert_pt_dynamic at p_lx_elf.cpp:5239.
- CVE-2021-43311Mar 24, 2023affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5382.
- CVE-2023-23457Jan 12, 2023affected < 4.0.1-bp154.4.3.1fixed 4.0.1-bp154.4.3.1
A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.
- CVE-2023-23456Jan 12, 2023affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.
- CVE-2021-30501May 26, 2021affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.
- CVE-2021-30500May 26, 2021affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.
- CVE-2021-20285Mar 26, 2021affected < 4.0.2-bp154.4.6.1fixed 4.0.2-bp154.4.6.1
A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from this vulnerability is to syst