PT-2017-14041 · Radare2 · Radare2

Fumfel

·

Published

2017-10-16

·

Updated

2017-10-27

·

CVE-2017-15385

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions radare2 version 2.0.0
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash, or possibly have other unspecified impacts through a crafted ELF file. This is due to an invalid write in the r read le16 function when handling a maliciously crafted file.
Recommendations For radare2 version 2.0.0, consider avoiding the use of the store versioninfo gnu verdef function in libr/bin/format/elf/elf.c until a patch is available. As a temporary workaround, restrict the processing of untrusted ELF files to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15385

Affected Products

Radare2