Command Injection Vulnerability in radare2 by Radare Organization
CVE-2019-16718
7.8HIGH
What is CVE-2019-16718?
In radare2 prior to version 3.9.0, a command injection vulnerability exists within the bin_symbols() function in libr/core/cbin.c. By exploiting this weakness using a specially crafted executable file, an attacker could execute arbitrary shell commands, effectively leveraging the victim's permissions. This vulnerability arose due to inadequate fixes from a previous related issue (CVE-2019-14745) and improper management of embedded symbol names within executables.
