An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.
[
{
"product": "upx",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "upx 4.0"
}
]
}
]