ZeroHour

CVE-2021-20285

PoC
CVSS 3.1
6.6 medium
EPSS
<1%p53
Published
()
Modified
Description

A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from this vulnerability is to system availability.

Vendors
upx
Products
upx
Weakness
CWE-119, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

In the news

No ingested article mentions this CVE yet.