CVE-2017-16359NULL Pointer Dereference in Radare2

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 58.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 1
Latest updateMay 17

Description

In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/radare2< radare2 2.1.0+dfsg-1 (sid)
Ubunturadare/radare2< 2.3.0+dfsg-2
NVDradare/radare22.0.1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gc9v-8hgh-q477: In radare 22022-05-17
OSV
CVE-2017-16359: In radare 22017-11-01

📋Vendor Advisories

1
Debian
CVE-2017-16359: radare2 - In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_...2017