p_lx_elf.cpp in UPX 3.94 mishandles ELF headers, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by an Invalid Pointer Read in PackLinuxElf64::unpack().
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-10-06T07:00:00

Updated: 2024-08-05T19:42:22.454Z

Reserved: 2017-10-06T00:00:00

Link: CVE-2017-15056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-10-06T07:29:00.207

Modified: 2017-11-01T12:56:45.483

Link: CVE-2017-15056

cve-icon Redhat

No data.