PT-2022-23135 · Rizin · Rizin

·

CVE-2022-36039

·

Published

2022-09-06

·

Updated

2022-09-27

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rizin versions 0.4.0 and prior
Description The issue affects a UNIX-like reverse engineering framework and command-line toolset, allowing an attacker to execute code on a user's machine when a malicious DEX file is opened. This is due to an out-of-bounds write when parsing DEX files.
Recommendations For versions 0.4.0 and prior, update to a patched version available on the dev branch of the repository to resolve the issue. As a temporary workaround, consider avoiding the use of the DEX file parsing functionality until the patch is applied.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-36039
GHSA-PR85-HV85-45PG

Affected Products

Rizin