CVE-2018-20459
published 2018-12-25CVE-2018-20459: In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by…
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.93%
56.7th percentile
In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20457.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | radare2 | < radare2 3.2.1+dfsg-1 (sid) | radare2 3.2.1+dfsg-1 (sid) |
| libcaca_project | libcaca | >= 0 < 0.99.beta18-1ubuntu5.1 | 0.99.beta18-1ubuntu5.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2ubuntu0.16.04.1 | 0.99.beta19-2ubuntu0.16.04.1 |
| libcaca_project | libcaca | >= 0 < 0.99.beta19-2ubuntu0.18.04.1 | 0.99.beta19-2ubuntu0.18.04.1 |
| radare | radare2 | <= 3.1.3 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-phjv-rf2x-c3qw: In radare2 through 3
ghsa_unreviewed·2022-05-13·CVSS 5.5
CVE-2018-20457 [MEDIUM] CWE-125 GHSA-phjv-rf2x-c3qw: In radare2 through 3
In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20459.
GHSA
GHSA-q3jx-mgc3-c89p: In radare2 through 3
ghsa_unreviewed·2022-05-13·CVSS 5.5
CVE-2018-20459 [MEDIUM] CWE-125 GHSA-q3jx-mgc3-c89p: In radare2 through 3
In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20457.
OSV
libcaca vulnerabilities
osv·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
libcaca vulnerabilities
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
OSV
CVE-2018-20457: In radare2 through 3
osv·2018-12-25·CVSS 5.5
CVE-2018-20457 [MEDIUM] CVE-2018-20457: In radare2 through 3
In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20459.
OSV
CVE-2018-20459: In radare2 through 3
osv·2018-12-25·CVSS 5.5
CVE-2018-20459 [MEDIUM] CVE-2018-20459: In radare2 through 3
In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20457.
Ubuntu
libcaca vulnerabilities
vendor_ubuntu·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
Title: libcaca vulnerabilities
Summary: Several security issues were fixed in libcaca.
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libcaca vulnerabilities
vendor_ubuntu·2019-01-15·CVSS 5.5
CVE-2018-20544 [MEDIUM] libcaca vulnerabilities
Title: libcaca vulnerabilities
Summary: Several security issues were fixed in libcaca.
USN-3860-1 fixed a vulnerability in libcaca. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-20544)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-20545, CVE-2018-20548, CVE-2018-20459)
It was discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information.
(CVE-2018-20546, CVE-2018-20547)
Instructions: In general, a standard system update
Debian
CVE-2018-20457: radare2 - In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c a...
vendor_debian·2018·CVSS 5.5
CVE-2018-20457 [MEDIUM] CVE-2018-20457: radare2 - In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c a...
In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20459.
Scope: local
sid: resolved (fixed in 3.2.1+dfsg-1)
Debian
CVE-2018-20459: radare2 - In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/arma...
vendor_debian·2018·CVSS 5.5
CVE-2018-20459 [MEDIUM] CVE-2018-20459: radare2 - In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/arma...
In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20457.
Scope: local
sid: resolved (fixed in 3.2.1+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 radare2: Multiple vulnerabilities
bugzilla·2019-01-07·CVSS 5.5
CVE-2018-20455 [MEDIUM] CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 radare2: Multiple vulnerabilities
CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 radare2: Multiple vulnerabilities
CVE-2018-20455
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash via a stack-based buffer overflow) by crafting an input file, a related issue to CVE-2018-20456.
https://github.com/radare/radare2/commit/9b46d38dd3c4de6048a488b655c7319f845af185
https://github.com/radare/radare2/issues/12373
CVE-2018-20456
In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related i
Bugzilla
CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 radare2: Multiple vulnerabilities [fedora-all]
bugzilla·2019-01-07·CVSS 5.5
CVE-2018-20455 [MEDIUM] CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 radare2: Multiple vulnerabilities [fedora-all]
CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 radare2: Multiple vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fe
2018-12-25
Published