An Integer overflow in the getElfSections function in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an allocation of excessive memory.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Apr 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Upx
Upx upx |
|
CPEs | cpe:2.3:a:upx:upx:3.95:*:*:*:*:*:*:* | |
Vendors & Products |
Upx Project
Upx Project upx |
Upx
Upx upx |

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T00:12:43.398Z
Reserved: 2019-07-27T00:00:00
Link: CVE-2019-14295

No data.

Status : Modified
Published: 2019-07-27T19:15:12.050
Modified: 2025-04-11T12:27:55.013
Link: CVE-2019-14295

No data.