Bug ID 1207122
Summary VUL-0: CVE-2023-23457: upx: SEGV on PackLinuxElf64:invert_pt_dynamic() in p_lx_elf.cpp
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.5
Hardware Other
URL https://smash.suse.de/issue/353588/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee jengelh@inai.de
Reporter cathy.hu@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

rh#2160382

A Segmentation fault was found in UPX in invert_pt_dynamic() function in
p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory
address access that could lead to a denial of service.

https://github.com/upx/upx/issues/631
https://github.com/upx/upx/commit/779b648c5f6aa9b33f4728f79dd4d0efec0bf860

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2160382
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-23457
https://www.cve.org/CVERecord?id=CVE-2023-23457
https://github.com/upx/upx/commit/779b648c5f6aa9b33f4728f79dd4d0efec0bf860
https://github.com/upx/upx/issues/631


You are receiving this mail because: