Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-04-11 12:33:51 +00:00
parent 7dc0f39dd3
commit 9add3248e2
27 changed files with 337 additions and 12 deletions
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x77-qmhw-v3hg",
"modified": "2022-05-24T17:18:54Z",
"modified": "2025-04-11T12:31:38Z",
"published": "2022-05-24T17:18:54Z",
"aliases": [
"CVE-2019-20805"
],
"details": "p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-190"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pmq-77vh-vh7v",
"modified": "2023-01-20T18:30:23Z",
"modified": "2025-04-11T12:31:38Z",
"published": "2022-05-24T17:05:12Z",
"aliases": [
"CVE-2019-20051"
@@ -23,6 +23,14 @@
"type": "WEB",
"url": "https://github.com/upx/upx/issues/313"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUTVSTXAFTD552NO2K2RIF6MDQEHP3BE"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5339-45c2-mh5v",
"modified": "2022-05-24T19:03:32Z",
"modified": "2025-04-11T12:31:38Z",
"published": "2022-05-24T19:03:32Z",
"aliases": [
"CVE-2021-30500"
],
"details": "Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-68mf-gv4w-rh82",
"modified": "2022-07-11T00:00:18Z",
"modified": "2025-04-11T12:31:38Z",
"published": "2022-05-24T19:02:26Z",
"aliases": [
"CVE-2020-24119"
@@ -27,6 +27,14 @@
"type": "WEB",
"url": "https://cwe.mitre.org/data/definitions/126.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JE54WKVU7MATB4WZD3MJFBAHFRJ3NTQX"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSQRO7YC72PSYDQG4PQLQYXZTZE3B4YV"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JE54WKVU7MATB4WZD3MJFBAHFRJ3NTQX"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-97cx-745f-9p9g",
"modified": "2023-01-20T18:30:23Z",
"modified": "2025-04-11T12:31:38Z",
"published": "2022-05-24T17:05:11Z",
"aliases": [
"CVE-2019-20021"
@@ -23,6 +23,14 @@
"type": "WEB",
"url": "https://github.com/upx/upx/issues/315"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUTVSTXAFTD552NO2K2RIF6MDQEHP3BE"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-phmx-286h-jcc3",
"modified": "2022-05-24T17:05:12Z",
"modified": "2025-04-11T12:31:38Z",
"published": "2022-05-24T17:05:12Z",
"aliases": [
"CVE-2019-20053"
],
"details": "An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xvcg-hv6h-729g",
"modified": "2022-05-13T01:28:42Z",
"modified": "2025-04-11T12:31:38Z",
"published": "2022-05-13T01:28:42Z",
"aliases": [
"CVE-2018-11243"
@@ -31,6 +31,14 @@
"type": "WEB",
"url": "https://github.com/upx/upx/blob/devel/NEWS"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUTVSTXAFTD552NO2K2RIF6MDQEHP3BE"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D7XU42G6MUQQXHWRP7DCF2JSIBOJ5GOO"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-125",
"CWE-787"
],
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-125"
],
"severity": "HIGH",
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-119"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-763"
],
"severity": "MODERATE",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-125"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-369"
],
"severity": "MODERATE",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-125"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-763"
],
"severity": "MODERATE",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-787"
],
"severity": "HIGH",

Some files were not shown because too many files have changed in this diff Show More