CVE-2017-16869 describes an invalid memory access vulnerability in UPX 3.94, specifically within the p_mach.cpp file's canPack and unpack functions, triggered by a crafted Mach-O file. This could lead to a denial of service (application crash) or potentially other unspecified impacts. The vulnerability is rated High severity (CVSS 7.8) due to its potential for high impact on confidentiality, integrity, and availability, requiring user interaction (UI:R) but with low attack complexity (AC:L). Despite the high CVSS score, there is no known exploit code available (Metasploit, Nuclei, ExploitDB: None), it is not listed on the KEV catalog, and there is no community discussion or media coverage, indicating a lack of active exploitation or public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.94CPE matchmatch criteria | cpe:2.3:a:upx:upx:3.94:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.