PT-2023-12300 · Rizin · Rizin

Ghost

·

Publicado

2023-03-24

·

Atualizado

2025-02-25

·

CVE-2021-3674

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rizin (affected versions not specified)
Description A flaw was found in the create section from phdr function, which allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, leading to memory corruption and possibly code execution through the binary object's callback function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2021-3674

Produtos afetados

Rizin