Bug ID | 1143838 |
---|---|
Summary | VUL-1: CVE-2019-14295: upx: integer overflow in getElfSections function in p_vmlinx.cpp |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | Leap 15.0 |
Hardware | Other |
URL | https://smash.suse.de/issue/238126/ |
OS | Other |
Status | NEW |
Severity | Minor |
Priority | P5 - None |
Component | Security |
Assignee | crrodriguez@opensuse.org |
Reporter | atoptsoglou@suse.com |
QA Contact | security-team@suse.de |
Found By | Security Response Team |
Blocker | --- |
rh#1735667 An Integer overflow in the getElfSections function in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an allocation of excessive memory. Reference: https://github.com/upx/upx/issues/286 References: https://bugzilla.redhat.com/show_bug.cgi?id=1735667 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-14295 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-14295.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14295 http://www.cvedetails.com/cve/CVE-2019-14295/ https://github.com/upx/upx/issues/286