CVE-2017-15931: High severity radare2 vulnerability
Published Oct 27, 2017
·Updated
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in storeversioninfognuverneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.
Affected Software
1 affected component
Radare Radare2=2.0.1
Remediation
Patch Available
Event History
Oct 27, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15931?
CVE-2017-15931 is classified as a high severity vulnerability due to its potential for causing application crashes on affected systems.
2
How do I fix CVE-2017-15931?
To fix CVE-2017-15931, users should upgrade to a patched version of radare2 that addresses this vulnerability.
3
What systems are affected by CVE-2017-15931?
CVE-2017-15931 specifically affects 32-bit systems running radare2 version 2.0.1.
4
What type of vulnerability is CVE-2017-15931?
CVE-2017-15931 is an integer exception vulnerability that can lead to invalid memory access.
5
Can crafted ELF files exploit CVE-2017-15931?
Yes, crafted ELF files can exploit CVE-2017-15931 by triggering the integer exception in the radare2 application.