PT-2017-14370 · Radare2 · Radare2

Gsharpsh00Ter

·

Publicado

2017-11-01

·

Atualizado

2017-11-13

·

CVE-2017-16357

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions radare2 version 2.0.1
Description A memory corruption issue exists due to improper sh size validation when allocating memory. This is demonstrated by an invalid free in the store versioninfo gnu verdef() and store versioninfo gnu verneed() functions in libr/bin/format/elf/elf.c.
Recommendations For radare2 version 2.0.1, as a temporary workaround, consider restricting access to the affected functions store versioninfo gnu verdef() and store versioninfo gnu verneed() until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-16357

Produtos afetados

Radare2