VDB

CVE-2024-3209

CVE-2024-3209 PUBLISHED CVSS 5.5 MEDIUM

A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

EPSS 0.37% · 59.0th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.37%
59.0th percentile

Affected Products

VendorProductVersions
n/aUPX4.2.0, 4.2.2, 4.2.1
upxupx0, 0, 0
fedoraprojectfedora38, 39, 40

Timeline

  • Apr 2, 2024 CVE Published
  • Apr 3, 2024 EPSS Score
  • Apr 28, 2024 EPSS Score
  • May 24, 2024 EPSS Score
  • Jun 19, 2024 EPSS Score
  • Jul 14, 2024 EPSS Score
  • Aug 9, 2024 EPSS Score
  • Sep 3, 2024 EPSS Score
  • Sep 28, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Nov 18, 2024 EPSS Score
  • Dec 14, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›