CVE-2022-1061Heap-based Buffer Overflow in Radare2

Severity
7.5HIGHNVD
EPSS
0.3%
top 49.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMar 25

Description

Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5radareorg/radareorg_radare2unspecified5.6.8
NVDradare/radare2< 5.6.8
debiandebian/radare2< radare2 5.9.0+dfsg-1 (sid)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hgxh-r733-qxg7: Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 52022-03-25
OSV
CVE-2022-1061: Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 52022-03-24

📋Vendor Advisories

1
Debian
CVE-2022-1061: radare2 - Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prio...2022