A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24119
Reference (s):
- https://github.com/upx/upx/issues/388
- FEDORA:FEDORA-2021-737766a313
- URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/VSQRO7YC72PSYDQG4PQLQYXZTZE3B4YV/
- FEDORA:FEDORA-2021-ceb9db8de0
- URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/JE54WKVU7MATB4WZD3MJFBAHFRJ3NTQX/

