Advisories ยป MGASA-2023-0052

Updated upx packages fix security vulnerability

Publication date: 20 Feb 2023
Modification date: 20 Feb 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2023-23456 , CVE-2023-23457

Description

Denial of service due to heap-based buffer overflow issue in UPX in
PackTmt::pack() in p_tmt.cpp file. (CVE-2023-23456)
Denial of service due to segmentation fault in UPX in
PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. (CVE-2023-23457)
                

References

SRPMS

8/core