alpine · CVE-2021-43315

Quick triage

Priority: high Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2021-43315: 1 source package rows (upx); 5 state rows across 2 repos (3.22-community, edge-community); fixed 0, open 5.

Description:

A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5349

cvelogic Threat Intelligence