An Integer overflow in the getElfSections function in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an allocation of excessive memory.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-07-27T18:40:33

Updated: 2019-08-11T03:06:15

Reserved: 2019-07-27T00:00:00


Link: CVE-2019-14295

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-07-27T19:15:12.050

Modified: 2023-11-07T03:04:52.930


Link: CVE-2019-14295

JSON object: View

cve-icon Redhat Information

No data.

CWE