Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-20456

Опубликовано: 25 дек. 2018
Источник: nvd
CVSS3: 5.5
CVSS2: 4.3
EPSS Низкий

Описание

In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:radare:radare2:*:*:*:*:*:*:*:*
Версия до 3.1.1 (исключая)

EPSS

Процентиль: 40%
0.0018
Низкий

5.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 7 лет назад

In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455.

CVSS3: 5.5
debian
около 7 лет назад

In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p ...

CVSS3: 5.5
github
больше 3 лет назад

In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455.

EPSS

Процентиль: 40%
0.0018
Низкий

5.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-125