PT-2022-23691 · Redex · Redex

Published

2022-11-10

·

Updated

2023-07-21

·

CVE-2022-36938

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Redex versions prior to commit 3b44c64
Description The issue concerns the DexLoader function get stringidx fromdex() in Redex, which can load an out of bound address when loading the string index table. This could potentially allow remote code execution during the processing of a 3rd party Android APK file.
Recommendations For Redex versions prior to commit 3b44c64, update to a version that includes the fix for the get stringidx fromdex() function to prevent potential remote code execution. As a temporary workaround, consider restricting the processing of 3rd party Android APK files until the issue is resolved.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2022-36938

Affected Products

Redex