PT-2017-14370 · Radare2 · Radare2
Gsharpsh00Ter
·
Published
2017-11-01
·
Updated
2017-11-13
·
CVE-2017-16357
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
radare2 version 2.0.1
Description
A memory corruption issue exists due to improper sh size validation when allocating memory. This is demonstrated by an invalid free in the store versioninfo gnu verdef() and store versioninfo gnu verneed() functions in libr/bin/format/elf/elf.c.
Recommendations
For radare2 version 2.0.1, as a temporary workaround, consider restricting access to the affected functions store versioninfo gnu verdef() and store versioninfo gnu verneed() until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Radare2