Rizin has stack-based buffer overflow when parsing GDB registers profile files
CVE-2023-27590
7.8HIGH
What is CVE-2023-27590?
The Rizin reverse engineering framework is affected by a stack-based buffer overflow vulnerability. Specifically, in versions prior to 0.5.1, the handling of GDB registers profile files can lead to overflow when fields such as name, type, or groups contain oversized values. This issue occurs when users attempt to open untrusted GDB register files using the drpg or arpg commands, exposing them to potential exploits. It is crucial for users to inspect these profiles carefully before use as a temporary measure until a patch is implemented. A fix has been provided in commit d6196703d89c84467b600ba2692534579dc25ed4.
Affected Version(s)
rizin <= 0.5.1
