CVE-2021-20285

Description


A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from this vulnerability is to system availability.

Related CPE's


References


ExploitIssue TrackingThird Party Advisory

Issue TrackingThird Party Advisory

CvssV3 impact


BaseSeverity

MEDIUM

ConfidentialityImpact

LOW

AttackComplexity

LOW

Scope

UNCHANGED

AttackVector

LOCAL

AvailabilityImpact

HIGH

IntegrityImpact

LOW

PrivilegesRequired

NONE

BaseScore

6.6

VectorString

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Version

3.1

UserInteraction

REQUIRED

CvssV2 impact


AccessComplexity

MEDIUM

ConfidentialityImpact

PARTIAL

AvailabilityImpact

COMPLETE

IntegrityImpact

PARTIAL

BaseScore

8.3

VectorString

AV:N/AC:M/Au:N/C:P/I:P/A:C

Version

2.0

AccessVector

NETWORK

Authentication

NONE