CVE-2020-27799

A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
VendorProductVersion
upxupx
4.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
upx-ucl
bullseye
unimportant
sid
4.2.4-1
fixed
trixie
4.2.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
upx-ucl
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needed
focal
needed
bionic
not-affected
xenial
not-affected
trusty
ignored