VDB
CVE-2025-2849
CVE-2025-2849
PUBLISHED
CVSS 3.299999952316284 LOW
A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0. Affected is the function PackLinuxElf64::un_DT_INIT of the file src/p_lx_elf.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The patch is identified as e0b6ff192412f5bb5364c1948f4f6b27a0cd5ea2. It is recommended to apply a patch to fix this issue.
EPSS 0.30% · 20.6th percentile
Risk Scores
CVSS 3.1
3.299999952316284
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.30%
20.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | UPX | 5.0 |
| upx | upx | 0 |
Timeline
- Mar 27, 2025 CVE Published
- Mar 27, 2025 CVE Updated
- Mar 28, 2025 EPSS Score
- Mar 29, 2025 Coalition ESS Score
- Apr 11, 2025 EPSS Score
- Apr 24, 2025 EPSS Score
- May 8, 2025 EPSS Score
- May 18, 2025 Coalition ESS Score
- May 21, 2025 EPSS Score
- Jun 4, 2025 EPSS Score
- Jun 17, 2025 EPSS Score
- Jul 1, 2025 EPSS Score
References
- https://github.com/upx/upx/issues/898 discussion
- VDB-301494 | UPX p_lx_elf.cpp un_DT_INIT heap-based overflow vdb
- VDB-301494 | CTI Indicators (IOB, IOC, IOA) url
- Submit #522371 | upx 5.0.0 Buffer Overflow third-party-advisory
- https://github.com/user-attachments/files/19307868/input.zip exploit
- https://github.com/upx/upx/issues/898#issuecomment-2734082143 discussion
- https://nvd.nist.gov/vuln/detail/CVE-2025-2849 advisory
- https://github.com/upx/upx/commit/e0b6ff192412f5bb5364c1948f4f6b27a0cd5ea2 fix