PT-2022-8869 · Radare2+1 · Radare2+1

X0Urc3

·

Published

2020-05-30

·

Updated

2022-08-22

·

CVE-2020-27795

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions radare2 (affected versions not specified)
Description A segmentation fault was discovered in radare2 when using the adf command with no or incorrect arguments. This issue arises from the anal fcn data function in libr/core/cmd anal.c, where r anal get fcn in returns a null pointer for fcn, leading to a segmentation fault later in ensure fcn range.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2049
CVE-2020-27795

Affected Products

Alt Linux
Radare2