Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 7, 8: MGASA-2021-0241 Critical: Upx Buffer Overflow and DoS Risk

mageia
Calendar Grey June 8, 2021
Dist Mageia Esm H88
Freshly released upx updates in Mageia tackle crucial security vulnerabilities, effectively mitigating risks related to memory overflow and service interruption threats.
The updated package fixes security vulnerabilities: A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect

Summary

The updated package fixes security vulnerabilities:
A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect. (CVE-2020-24119)
A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from this vulnerability is to system availability. (CVE-2021-20285)

References

- https://bugs.mageia.org/show_bug.cgi?id=29016

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/G3BQABK4YLXENDJBLDMHAIPRTC3ZMLYK/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/VSQRO7YC72PSYDQG4PQLQYXZTZE3B4YV/

-

- https://www.cve.org/CVERecord?id=CVE-2020-24119

- https://www.cve.org/CVERecord?id=CVE-2021-20285

Resolution

SRPMS

- 8/core/upx-3.96-2.1.mga8

- 7/core/upx-3.96-1.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 08 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0241.html
Type: security
CVE: CVE-2020-24119, CVE-2021-20285

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here