Lucene search

K
suseSuseOPENSUSE-SU-2020:0163-1
HistoryFeb 04, 2020 - 12:00 a.m.

Security update for upx (moderate)

2020-02-0400:00:00
lists.opensuse.org
35

0.017 Low

EPSS

Percentile

87.9%

An update that fixes 5 vulnerabilities is now available.

Description:

This update for upx to version 3.96 fixes the following issues:

  • CVE-2019-1010048: Fixed a denial of service in
    PackLinuxElf32::PackLinuxElf32help1() (boo#1141777).

  • CVE-2019-14296: Fixed a denial of service in canUnpack() (boo#1143839).

  • CVE-2019-20021: Fixed a heap-based buffer over-read in canUnpack()
    (boo#1159833).

  • CVE-2019-20053: Fixed a denial of service in canUnpack() (boo#1159920).

  • CVE-2018-11243: Fixed a denial of service in PackLinuxElf64::unpack()
    (boo#1094138).

  • Update to version 3.96

    • Bug fixes: [CVE-2019-1010048, boo#1141777] [CVE-2019-14296,
      boo#1143839] [CVE-2019-20021, boo#1159833] [CVE-2019-20053,
      boo#1159920] [CVE-2018-11243 partially - ticket 206 ONLY, boo#1094138]
  • Update to version 3.95

    • Flag --force-pie when ET_DYN main program is not marked as DF_1_PIE
    • Better compatibility with varying layout of address space on Linux
    • Support for 4 PT_LOAD layout in ELF generated by binutils-2.31
    • bug fixes, particularly better diagnosis of malformed input
    • bug fixes - see https://github.com/upx/upx/milestone/4

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.1:

    zypper in -t patch openSUSE-2020-163=1

OSVersionArchitecturePackageVersionFilename
openSUSE Leap15.1x86_64< - openSUSE Leap 15.1 (x86_64):- openSUSE Leap 15.1 (x86_64):.x86_64.rpm