Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file. Upstream issue: https://github.com/upx/upx/issues/48 Upstream patch: https://github.com/upx/upx/commit/90279abdfcd235172eab99651043051188938dcc
Created upx tracking bugs for this issue: Affects: epel-all [bug 1948693] Affects: fedora-all [bug 1948694]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
(In reply to Pedro Sampaio from comment #0) > Null pointer dereference was found in upx PackLinuxElf::canUnpack() in > p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute > arbitrary code and cause a denial of service via a crafted file. > > Upstream issue: > > https://github.com/upx/upx/issues/48 > > Upstream patch: > > https://github.com/upx/upx/commit/90279abdfcd235172eab99651043051188938dcc Should the upstream issue to b referenced be https://github.com/upx/upx/issues/485 (missing last 5 digit in the issue number instead of 48)?
Yes, that's correct.