openSUSE-SU-2023:0088-1
Dashboard / Vulnerabilities / openSUSE-SU-2023:0088-1
openSUSE-SU-2023:0088-1
Summary: Security update for upx
Details: upx was updated to fix the following issues: Update to release 4.0.2 * Fix unpack of ELF x86-64 that failed with 'CantUnpackException: corrupt b_info' * Resolve SEGV on PackLinuxElf64::invert_pt_dynamic - CVE-2021-30500: Fixed Null pointer dereference in PackLinuxElf:canUnpack() in p_lx_elf.cpp - CVE-2021-30501: Fixed Assertion abort in function MemBuffer:alloc() - CVE-2021-43311: Fixed Heap-based buffer overflow in PackLinuxElf32:elf_lookup() at p_lx_elf.cpp - CVE-2021-43312: Fixed Heap-based buffer overflow in PackLinuxElf64:invert_pt_dynamic at p_lx_elf.cpp:5239 - CVE-2021-43313: Fixed Heap-based buffer overflow in PackLinuxElf32:invert_pt_dynamic at p_lx_elf.cpp:1688 - CVE-2021-43314: Fixed Heap-based buffer overflows in PackLinuxElf32:elf_lookup() at p_lx_elf.cp - CVE-2021-43315: Fixed Heap-based buffer overflows in PackLinuxElf32:elf_lookup() at p_lx_elf.cp - CVE-2021-43316: Fixed Heap-based buffer overflow in func get_le64() - CVE-2021-43317: Fixed Heap-based buffer overflows in PackLinuxElf64:elf_lookup() at p_lx_elf.cp - CVE-2023-23456: Fixed heap-buffer-overflow in PackTmt:pack() - CVE-2023-23457: Fixed SEGV on PackLinuxElf64:invert_pt_dynamic() in p_lx_elf.cpp
References: https://lists.opensuse.org/archives/list/[email protected]/thread/XLSYENIWX7YMHJJKVRBH2CPDXM5X3IW6/, https://bugzilla.suse.com/1183510, https://bugzilla.suse.com/1184701, https://bugzilla.suse.com/1184702, https://bugzilla.suse.com/1207121, https://bugzilla.suse.com/1207122, https://bugzilla.suse.com/1209765, https://bugzilla.suse.com/1209766, https://bugzilla.suse.com/1209767, https://bugzilla.suse.com/1209768, https://bugzilla.suse.com/1209769, https://bugzilla.suse.com/1209770, https://bugzilla.suse.com/1209771, https://www.suse.com/security/cve/CVE-2021-20285, https://www.suse.com/security/cve/CVE-2021-30500, https://www.suse.com/security/cve/CVE-2021-30501, https://www.suse.com/security/cve/CVE-2021-43311, https://www.suse.com/security/cve/CVE-2021-43312, https://www.suse.com/security/cve/CVE-2021-43313, https://www.suse.com/security/cve/CVE-2021-43314, https://www.suse.com/security/cve/CVE-2021-43315, https://www.suse.com/security/cve/CVE-2021-43316, https://www.suse.com/security/cve/CVE-2021-43317, https://www.suse.com/security/cve/CVE-2023-23456, https://www.suse.com/security/cve/CVE-2023-23457
Affected packages
Package
Name: upx
Purl: pkg:rpm/suse/upx&distro=SUSE%20Package%20Hub%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
