CVE-2017-16869: Upx

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

p_mach.cpp in UPX 3.94 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted Mach-O file, related to canPack and unpack functions. NOTE: the vendor has stated "there is no security implication whatsoever.

Affected products

  • Upx Upx: version 3.94 only

Published 2017-11-17. Last modified 2026-06-17.