Debian Radare2 vulnerabilities

154 known vulnerabilities affecting debian/radare2.

Total CVEs
154
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH51MEDIUM42LOW47

Vulnerabilities

Page 6 of 8
CVE-2018-14016MEDIUMCVSS 5.5fixed in radare2 2.8.0+dfsg-1 (sid)2018
CVE-2018-14016 [MEDIUM] CVE-2018-14016: radare2 - The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows r... The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Mini Crash Dump file. Scope: local sid: resolved (fixed in 2.8.0+dfsg-1)
debian
CVE-2018-14015MEDIUMCVSS 5.5fixed in radare2 2.8.0+dfsg-1 (sid)2018
CVE-2018-14015 [MEDIUM] CVE-2018-14015: radare2 - The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers ... The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c. Scope: local sid: resolved (fixed in 2.8.0+dfsg-1)
debian
CVE-2018-8810MEDIUMCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-8810 [MEDIUM] CVE-2018-8810: radare2 - In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t ... In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted Mach-O file. Scope: local sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2018-11375LOWCVSS 5.52018
CVE-2018-11375 [MEDIUM] CVE-2018-11375: radare2 - The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a de... The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. Scope: local sid: resolved
debian
CVE-2018-11383LOWCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-11383 [MEDIUM] CVE-2018-11383: radare2 - The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a... The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted ELF file because of an uninitialized variable in the CPSE handler in libr/anal/p/anal_avr.c. Scope: local sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2018-12321LOWCVSS 7.8fixed in radare2 2.7.0+dfsg-1 (sid)2018
CVE-2018-12321 [HIGH] CVE-2018-12321: radare2 - There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/... There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java binary file. Scope: local sid: resolved (fixed in 2.7.0+dfsg-1)
debian
CVE-2018-11380LOWCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-11380 [MEDIUM] CVE-2018-11380: radare2 - The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to caus... The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file. Scope: local sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2018-20455LOWCVSS 5.5fixed in radare2 3.1.2+dfsg-1 (sid)2018
CVE-2018-20455 [MEDIUM] CVE-2018-20455: radare2 - In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_n... In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash via a stack-based buffer overflow) by crafting an input file, a related issue to CVE-2018-20456. Scope: local sid: resolved (fixed in 3.1.2+dfsg-1)
debian
CVE-2018-20456LOWCVSS 5.5fixed in radare2 3.1.2+dfsg-1 (sid)2018
CVE-2018-20456 [MEDIUM] CVE-2018-20456: radare2 - In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_n... In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455. Scope: local sid: resolved (fixed in 3.1.2+dfsg-1)
debian
CVE-2018-11377LOWCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-11377 [MEDIUM] CVE-2018-11377: radare2 - The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause ... The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. Scope: local sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2018-11378LOWCVSS 7.8fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-11378 [HIGH] CVE-2018-11378: radare2 - The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspeci... The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file. Scope: local sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2018-11379LOWCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-11379 [MEDIUM] CVE-2018-11379: radare2 - The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause ... The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted PE file. Scope: local sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2018-11381LOWCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-11381 [MEDIUM] CVE-2018-11381: radare2 - The string_scan_range() function in radare2 2.5.0 allows remote attackers to cau... The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. Scope: local sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2018-19843LOWCVSS 5.5fixed in radare2 3.1.0+dfsg-1 (sid)2018
CVE-2018-19843 [MEDIUM] CVE-2018-19843: radare2 - opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cau... opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2. Scope: local sid: resolved (fixed in 3.1.0+dfsg-1)
debian
CVE-2018-20460LOWCVSS 5.5fixed in radare2 3.1.2+dfsg-1 (sid)2018
CVE-2018-20460 [MEDIUM] CVE-2018-20460: radare2 - In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armas... In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial-of-service (application crash caused by stack-based buffer overflow) by crafting an input file. Scope: local sid: resolved (fixed in 3.1.2+dfsg-1)
debian
CVE-2018-10187LOWCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-10187 [MEDIUM] CVE-2018-10187: radare2 - In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op functi... In radare2 2.5.0, there is a heap-based buffer over-read in the dalvik_op function (libr/anal/p/anal_dalvik.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted DEX file. Note that this issue is different from CVE-2018-8809, which was patched earlier. Scope: local sid: resolved (fixed in 2.6.0+dfsg-1)
debian
CVE-2018-20457LOWCVSS 5.5fixed in radare2 3.2.1+dfsg-1 (sid)2018
CVE-2018-20457 [MEDIUM] CVE-2018-20457: radare2 - In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c a... In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20459. Scope: l
debian
CVE-2018-12320LOWCVSS 7.8fixed in radare2 2.7.0+dfsg-1 (sid)2018
CVE-2018-12320 [HIGH] CVE-2018-12320: radare2 - There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c... There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file. Scope: local sid: resolved (fixed in 2.7.0+dfsg-1)
debian
CVE-2018-20458LOWCVSS 5.5fixed in radare2 3.1.2+dfsg-1 (sid)2018
CVE-2018-20458 [MEDIUM] CVE-2018-20458: radare2 - In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyld... In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting an input file. Scope: local sid: resolved (fixed in 3.1.2+dfsg-1)
debian
CVE-2018-11384LOWCVSS 5.5fixed in radare2 2.6.0+dfsg-1 (sid)2018
CVE-2018-11384 [MEDIUM] CVE-2018-11384: radare2 - The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial ... The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file. Scope: local sid: resolved (fixed in 2.6.0+dfsg-1)
debian