CVE-2023-23456: Fedoraproject Fedora

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

Affected products

  • Fedoraproject Fedora: version 36 only; version 37 only
  • Upx Upx: before 2022-11-24 (fixed in 2022-11-24)

Published 2023-01-12. Last modified 2026-06-17.