Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2024-3209
HistoryApr 02, 2024 - 11:15 p.m.

CVE-2024-3209

2024-04-0223:15:55
Alpine Linux Development Team
security.alpinelinux.org
1
cve-2024-3209
upx
critical
buffer overflow
vdb-259055
vendor
unix

6.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.3%

A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

OSVersionArchitecturePackageVersionFilename
Alpine3.19-communitynoarchupx= 4.2.1-r0UNKNOWN

6.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.3%