Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14745

Опубликовано: 07 авг. 2019
Источник: debian
EPSS Низкий

Описание

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
radare2fixed3.9.0+dfsg-1package
radare2no-dsajessiepackage

Примечания

  • https://github.com/radare/radare2/pull/14690

  • When fixing this ussue make sure to not only apply the initial commits but

  • as well the followups to avoid opening CVE-2019-16718:

  • https://github.com/radareorg/radare2/commit/5411543a310a470b1257fb93273cdd6e8dfcb3af

  • https://github.com/radareorg/radare2/commit/dd739f5a45b3af3d1f65f00fe19af1dbfec7aea7

EPSS

Процентиль: 91%
0.07084
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 6 лет назад

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.

CVSS3: 7.8
nvd
больше 6 лет назад

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.

CVSS3: 7.8
github
больше 3 лет назад

In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.

EPSS

Процентиль: 91%
0.07084
Низкий