{"id":"MGASA-2020-0096","summary":"Updated upx packages fix security vulnerabilities","details":"The updated packages fix security vulnerabilities:\n\nPackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers\nto cause a denial of service (double free), limit the ability of a malware\nscanner to operate on the entire original data, or possibly have\n unspecified other impact via a crafted file. (CVE-2018-11243)\n\nA heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in\nUPX 3.95 via a crafted Mach-O file. (CVE-2019-20021)\n\nA floating-point exception was discovered in PackLinuxElf::elf_hash in\np_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash,\nwhich leads to denial of service. (CVE-2019-20051)\n\nAn invalid memory address dereference was discovered in the canUnpack\nfunction in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.\n(CVE-2019-20053)\n\nA denial of service in PackLinuxElf32::PackLinuxElf32help1().\n(CVE-2019-1010048)\n","modified":"2026-04-16T04:44:21.897306494Z","published":"2020-02-24T21:44:46Z","upstream":["CVE-2018-11243","CVE-2019-1010048","CVE-2019-20021","CVE-2019-20051","CVE-2019-20053"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2020-0096.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=26172"},{"type":"WEB","url":"https://lists.opensuse.org/opensuse-updates/2020-02/msg00012.html"},{"type":"WEB","url":"https://lists.opensuse.org/opensuse-updates/2020-02/msg00006.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO/"}],"affected":[{"package":{"name":"upx","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/upx?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.96-1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0096.json"}},{"package":{"name":"ucl","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/ucl?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.03-16.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2020-0096.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}