PT-2022-22244 · Rizin · Rizin

Published

2022-07-27

·

Updated

2023-03-30

·

CVE-2022-34612

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Rizin versions 0.4.0 and below
Description The issue is related to an integer overflow via the function get long object(). This allows attackers to cause a Denial of Service (DoS) via a crafted binary.
Recommendations For Rizin versions 0.4.0 and below, consider updating to a version above 0.4.0 to resolve the issue. As a temporary workaround, consider restricting the use of the get long object() function until a patch is available.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-34612

Affected Products

Rizin