PT-2022-23135 · Rizin · Rizin
M4Drat
·
Published
2022-09-06
·
Updated
2022-09-27
·
CVE-2022-36039
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rizin versions 0.4.0 and prior
Description
The issue affects a UNIX-like reverse engineering framework and command-line toolset, allowing an attacker to execute code on a user's machine when a malicious DEX file is opened. This is due to an out-of-bounds write when parsing DEX files.
Recommendations
For versions 0.4.0 and prior, update to a patched version available on the
dev branch of the repository to resolve the issue. As a temporary workaround, consider avoiding the use of the DEX file parsing functionality until the patch is applied.Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rizin