CVE-2024-11858
published 2024-12-15CVE-2024-11858: A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.78%
52.0th percentile
A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | radare2 | < radare2 5.9.8+dfsg-1 (sid) | radare2 5.9.8+dfsg-1 (sid) |
| radare | radare2 | <= 5.9.8 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r3c4-qgcj-4qp2: A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application
ghsa_unreviewed·2024-12-15
CVE-2024-11858 [HIGH] CWE-78 GHSA-r3c4-qgcj-4qp2: A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application
A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing
OSV
CVE-2024-11858: A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application
osv·2024-12-15·CVSS 7.8
CVE-2024-11858 [HIGH] CVE-2024-11858: A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application
A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing
Debian
CVE-2024-11858: radare2 - A flaw was found in Radare2, which contains a command injection vulnerability ca...
vendor_debian·2024·CVSS 8.6
CVE-2024-11858 [HIGH] CVE-2024-11858: radare2 - A flaw was found in Radare2, which contains a command injection vulnerability ca...
A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, leading to unintended behavior during file processing
Scope: local
sid: resolved (fixed in 5.9.8+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-15
Published