Improper Neutralization Vulnerability in Rizin by Rizinorg
CVE-2024-31668

9.1CRITICAL

Key Information:

Vendor

Rizinorg

Status
Vendor
CVE Published:
17 December 2024

What is CVE-2024-31668?

Rizin versions prior to 0.6.3 are susceptible to an improper neutralization vulnerability within the meta_set function in librz/analysis/meta. This flaw could allow an attacker to manipulate special elements in a way that could compromise the integrity of applications utilizing the Rizin software framework. Users are advised to upgrade to the latest version to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.