Vulnerabilities > CVE-2021-30501 - Reachable Assertion vulnerability in multiple products

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH

Summary

An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.

Vulnerable Configurations

Part Description Count
Application
Upx_Project
1
OS
Redhat
1
OS
Fedoraproject
1

Common Weakness Enumeration (CWE)