Debian Package Tracker
Register | Log in
Subscribe

upx-ucl

efficient live-compressor for executables

Choose email to subscribe with

general
  • source: upx-ucl (main)
  • version: 4.2.4-2
  • maintainer: Debian Commons (DMD)
  • uploaders: Bastian Germann [DMD]
  • arch: any
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.96-2
  • o-o-sec: 3.96-2+deb11u1
  • old-bpo: 4.2.4-1.1~bpo12+1
  • stable: 4.2.4-1.1
  • testing: 4.2.4-1.1
  • unstable: 4.2.4-2
versioned links
  • 3.96-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.96-2+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.2.2-3~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.2.4-1.1~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.2.4-1.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.2.4-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • upx-ucl (2 bugs: 0, 2, 0, 0)
action needed
A new upstream version is available: 5.2.1 high
A new upstream version 5.2.1 is available, you should consider packaging it.
Created: 2026-09-01 Last update: 2026-09-03 13:33
2 security issues in buster high

There are 2 open security issues in buster.

1 important issue:
  • CVE-2024-3209: A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
1 issue postponed or untriaged:
  • CVE-2023-23456: (needs triaging) A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.
Created: 2024-04-05 Last update: 2024-04-05 21:00
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2023-23456: A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.
Created: 2023-01-13 Last update: 2023-04-13 21:09
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-09-03 13:30
1 new commit since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit b6e7d9a4c1e570216a86c8754daf2fa85d4efebe
Author: Helmut Grohne <helmut@subdivi.de>
Date:   Sun Oct 13 21:17:31 2024 +0200

    Fix FTCBFS: Let debhelper choose the compiler (Closes: #1085088)
    
    upx-ucl fails to cross build from source, because debian/rules passes
    the $(CC) variable as compiler to cmake. As it happens CC defaults to
    cc and that only happens to be right for native compilation. Just
    deleting the assignment fixes things and still retains the ability to
    override the compiler, because cmake picks up the CC environment
    variable.


https://salsa.debian.org/api/v4/projects/debian%2Fupx-ucl API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-09-01 Last update: 2026-09-01 09:02
debian/patches: 3 patches to forward upstream low

Among the 6 debian patches available in version 4.2.4-2 of the package, we noticed the following issues:

  • 3 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2026-09-01 Last update: 2026-09-01 15:03
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.0).
Created: 2025-02-21 Last update: 2026-09-01 12:04
testing migrations
  • excuses:
    • Migration status for upx-ucl (4.2.4-1.1 to 4.2.4-2): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for upx-ucl/4.2.4-2: amd64: Regression ♻ (reference ♻), arm64: Reference test triggered, but real test failed already ♻, armhf: Regression ♻ (reference ♻), i386: Test triggered, ppc64el: Regression ♻ (reference ♻), riscv64: Regression ♻ (reference ♻)
    • ∙ ∙ Too young, only 2 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/u/upx-ucl.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-09-01] Accepted upx-ucl 4.2.4-2 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2026-08-31] Accepted upx-ucl 4.2.4-1.1~bpo12+1 (source) into oldstable-backports (Bastian Germann) (signed by: bage@debian.org)
  • [2025-04-26] upx-ucl 4.2.4-1.1 MIGRATED to testing (Debian testing watch)
  • [2025-04-16] Accepted upx-ucl 4.2.4-1.1 (source) into unstable (Matheus Polkorny) (signed by: Carlos Henrique Lima Melara)
  • [2024-12-11] Accepted upx-ucl 3.96-2+deb11u1 (source) into oldstable-security (Sylvain Beucler)
  • [2024-09-02] upx-ucl 4.2.4-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-30] Accepted upx-ucl 4.2.4-1 (source) into unstable (Robert Luberda)
  • [2024-04-23] Accepted upx-ucl 4.2.2-3~bpo12+1 (source amd64) into stable-backports (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2024-01-21] upx-ucl 4.2.2-3 MIGRATED to testing (Debian testing watch)
  • [2024-01-19] Accepted upx-ucl 4.2.2-3 (source) into unstable (Robert Luberda)
  • [2024-01-12] Accepted upx-ucl 4.2.2-2 (source) into unstable (Robert Luberda)
  • [2024-01-11] Accepted upx-ucl 4.2.2-1 (source) into unstable (Robert Luberda)
  • [2023-05-11] upx-ucl REMOVED from testing (Debian testing watch)
  • [2021-10-16] upx-ucl 3.96-3 MIGRATED to testing (Debian testing watch)
  • [2021-10-14] Accepted upx-ucl 3.96-3 (source) into unstable (Robert Luberda)
  • [2020-06-07] upx-ucl 3.96-2 MIGRATED to testing (Debian testing watch)
  • [2020-06-05] Accepted upx-ucl 3.96-2 (source) into unstable (Robert Luberda)
  • [2020-03-08] Accepted upx-ucl 3.96-1 (source) into unstable (Robert Luberda)
  • [2019-08-05] upx-ucl 3.95-2 MIGRATED to testing (Debian testing watch)
  • [2019-07-29] Accepted upx-ucl 3.95-2 (source amd64) into unstable (Robert Luberda)
  • [2018-08-31] upx-ucl 3.95-1 MIGRATED to testing (Debian testing watch)
  • [2018-08-28] Accepted upx-ucl 3.95-1 (source amd64) into unstable (Robert Luberda)
  • [2018-08-10] upx-ucl 3.94-5 MIGRATED to testing (Debian testing watch)
  • [2018-08-05] Accepted upx-ucl 3.95~git20180805-1 (source amd64) into experimental (Robert Luberda)
  • [2018-08-05] Accepted upx-ucl 3.94-5 (source amd64) into unstable (Robert Luberda)
  • [2017-12-28] upx-ucl 3.94-4 MIGRATED to testing (Debian testing watch)
  • [2017-12-22] Accepted upx-ucl 3.94+git20171222-1 (source amd64) into experimental (Robert Luberda)
  • [2017-12-22] Accepted upx-ucl 3.94-4 (source amd64) into unstable (Robert Luberda)
  • [2017-09-07] upx-ucl 3.94-3 MIGRATED to testing (Debian testing watch)
  • [2017-09-01] Accepted upx-ucl 3.94-3 (source amd64) into unstable (Robert Luberda)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 3
  • M&W: 0
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.2.4-1.1build1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing