PT-2017-14370 · Radare2 · Radare2
Gsharpsh00Ter
·
Publicado
2017-11-01
·
Atualizado
2017-11-13
·
CVE-2017-16357
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
radare2 version 2.0.1
Description
A memory corruption issue exists due to improper sh size validation when allocating memory. This is demonstrated by an invalid free in the store versioninfo gnu verdef() and store versioninfo gnu verneed() functions in libr/bin/format/elf/elf.c.
Recommendations
For radare2 version 2.0.1, as a temporary workaround, consider restricting access to the affected functions store versioninfo gnu verdef() and store versioninfo gnu verneed() until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Radare2