Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ogianatiempo

#17579of 53,635
15.3Total CVSS
Vulnerabilities · 2
High
2
PT-2022-11203
7.5
2022-01-02
Radare2 · Radare2 · CVE-2021-4021
**Name of the Vulnerable Software and Affected Versions** Radare2 versions prior to 5.6.2 **Description** A vulnerability was found in Radare2 where mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and Denial of Service (DoS). **Recommendations** For versions prior to 5.6.2, update to version 5.6.2 or later to resolve the issue. At the moment, there is no information about other mitigation measures for this vulnerability.
PT-2021-6794
7.8
2021-11-16
Rizin · Rizin · CVE-2021-43814
**Name of the Vulnerable Software and Affected Versions** Rizin versions up to and including 0.3.1 **Description** The issue is related to a heap-based out of bounds write in the `parse die()` function when reversing an AMD64 ELF binary with DWARF debug info. This can cause Rizin to crash or execute unintended actions when a malicious AMD64 ELF binary is opened. **Recommendations** For versions up to and including 0.3.1, users are advised to upgrade to a newer version to resolve the issue. As a temporary workaround, consider avoiding the use of the `parse die()` function when reversing AMD64 ELF binaries with DWARF debug info until a patch is available.