PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file.
References
Configurations
History
21 Nov 2024, 03:42
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00001.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00003.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00007.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00008.html - | |
References | () https://github.com/upx/upx/blob/devel/NEWS - Release Notes | |
References | () https://github.com/upx/upx/issues/206 - Exploit, Third Party Advisory | |
References | () https://github.com/upx/upx/issues/207 - Exploit, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUTVSTXAFTD552NO2K2RIF6MDQEHP3BE/ - |
07 Nov 2023, 02:51
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2018-05-18 17:29
Updated : 2024-11-21 03:42
NVD link : CVE-2018-11243
Mitre link : CVE-2018-11243
CVE.ORG link : CVE-2018-11243
JSON object : View
Products Affected
upx_project
- upx
CWE
CWE-415
Double Free