« List of all CVEs

CVE-2017-16357

Published: 11/1/2017 Last updated: 9/17/2024 Reserved: 11/1/2017

In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c, as demonstrated by an invalid free. This error is due to improper sh_size validation when allocating memory.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (2)

conf-radare2 radare2

Products affected (1)

Product Vendor Version
n/a n/a n/a

References (4)