CVE-2023-23456

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
12/01/2023
Last modified:
11/04/2025

Description

A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:upx:upx:*:*:*:*:*:*:*:* 2022-11-24 (excluding)
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*