CVE-2020-24119 log

Source
Severity Medium
Remote No
Type Information disclosure
Description
A heap buffer overflow read was discovered in upx 3.96 because the check in p_lx_elf.cpp is not perfect.
Group Package Affected Fixed Severity Status Ticket
AVG-1676 upx 3.96-2 Medium Vulnerable
References
https://github.com/upx/upx/issues/388
https://github.com/upx/upx/files/4958990/poc-heap-buffer-overflow-get_le32.tar.gz
https://github.com/upx/upx/commit/87b73e5cfdc12da94c251b2cd83bb01c7d9f616c