Wind River Support Network

HomeDefectsLIN1023-4497
Not to be fixed

LIN1023-4497 : Security Advisory - upx - CVE-2024-3209

Created: Apr 2, 2024    Updated: Apr 8, 2024
Resolved Date: Apr 7, 2024
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.



CREATE(Triage):(User=admin) CVE-2024-3209 (https://nvd.nist.gov/vuln/detail/CVE-2024-3209)
Live chat
Online