CVE-2021-43311
A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in
A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5382.
HIGH · CVSS 7.5
EPSS 0.00348
Act now
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0