PT-2023-12300 · Rizin · Rizin

Ghost

·

Published

2023-03-24

·

Updated

2025-02-25

·

CVE-2021-3674

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rizin (affected versions not specified)
Description A flaw was found in the create section from phdr function, which allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, leading to memory corruption and possibly code execution through the binary object's callback function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2021-3674

Affected Products

Rizin