← Back

CVE-2019-14295

nvd nist
Published: Jul 27, 2019Modified: Apr 11, 2025

JSON object

Loading...
5.5
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

An Integer overflow in the getElfSections function in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an allocation of excessive memory.

Affected (1)

Products: Upx: Upx
1 product
Upx
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.95

Timeline

No history available yet.