A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
                
            References
                    Configurations
                    History
                    11 Apr 2025, 12:27
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:upx:upx:4.0.0:*:*:*:*:*:*:* | |
| First Time | 
        
        Upx upx
         Upx  | 
21 Nov 2024, 05:14
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://cwe.mitre.org/data/definitions/126.html - Technical Description | |
| References | () https://github.com/upx/upx/issues/388 - Exploit, Issue Tracking, Patch, Third Party Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JE54WKVU7MATB4WZD3MJFBAHFRJ3NTQX/ - | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSQRO7YC72PSYDQG4PQLQYXZTZE3B4YV/ - | 
26 Oct 2022, 13:48
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (MISC) https://cwe.mitre.org/data/definitions/126.html - Technical Description | 
10 Jul 2022, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
        
        
  | 
28 May 2021, 19:43
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSQRO7YC72PSYDQG4PQLQYXZTZE3B4YV/ - Mailing List, Third Party Advisory | |
| References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JE54WKVU7MATB4WZD3MJFBAHFRJ3NTQX/ - Mailing List, Third Party Advisory | |
| CPE | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*  | 
27 May 2021, 03:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
        
        
  | 
Information
                Published : 2021-05-14 21:15
Updated : 2025-04-11 12:27
NVD link : CVE-2020-24119
Mitre link : CVE-2020-24119
CVE.ORG link : CVE-2020-24119
JSON object : View
Products Affected
                upx
- upx
 
fedoraproject
- fedora
 
CWE
                
                    
                        
                        CWE-125
                        
            Out-of-bounds Read
