PT-2017-14370 · Radare2 · Radare2

Gsharpsh00Ter

·

Published

2017-11-01

·

Updated

2017-11-13

·

CVE-2017-16357

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions radare2 version 2.0.1
Description A memory corruption issue exists due to improper sh size validation when allocating memory. This is demonstrated by an invalid free in the store versioninfo gnu verdef() and store versioninfo gnu verneed() functions in libr/bin/format/elf/elf.c.
Recommendations For radare2 version 2.0.1, as a temporary workaround, consider restricting access to the affected functions store versioninfo gnu verdef() and store versioninfo gnu verneed() until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16357

Affected Products

Radare2