PT-2018-12279 · Radare2+1 · Radare2+1

Macromachine

·

Publicado

2018-07-12

·

Atualizado

2025-03-18

·

CVE-2018-14015

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions radare2 version 2.7.0
Description The issue is related to a denial of service caused by an invalid read and application crash. This occurs when a crafted ELF file is processed due to missing input validation in the r bin dwarf parse comp unit function in libr/bin/dwarf.c, which is called by the sdb set internal function in sdb.c.
Recommendations For radare2 version 2.7.0, consider restricting the use of the sdb set internal function until a patch is available, or avoid processing untrusted ELF files to minimize the risk of exploitation.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2690
CVE-2018-14015

Produtos afetados

Alt Linux
Radare2