Remote Denial of Service in radare2 by ELF File Processing
CVE-2017-16805

5.5MEDIUM

Key Information:

Vendor

Radare

Status
Vendor
CVE Published:
3 October 2022

What is CVE-2017-16805?

In radare2 version 2.0.1, a vulnerability exists in the processing of ELF files within the libr/bin/dwarf.c component. Remote attackers can exploit this flaw to trigger an invalid read, leading to an application crash. The vulnerability is associated with the r_bin_dwarf_parse_comp_unit function in dwarf.c, and improper handling in sdb_set_internal function within sdb.c can be exploited to cause the targeted application to become unresponsive.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.