CVE-2017-15932: High severity radare2 vulnerability
Published Oct 27, 2017
·Updated
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in storeversioninfognuverdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.
Affected Software
1 affected component
Radare Radare2=2.0.1
Remediation
Patch Available
Event History
Oct 27, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15932?
CVE-2017-15932 has a moderate severity due to potential integrity issues caused by invalid memory access.
2
How do I fix CVE-2017-15932?
To fix CVE-2017-15932, update radare2 to the latest version that contains the patch for this vulnerability.
3
What systems are affected by CVE-2017-15932?
CVE-2017-15932 specifically affects radare2 version 2.0.1 running on 32-bit systems.
4
What type of vulnerability is CVE-2017-15932?
CVE-2017-15932 is categorized as an integer exception vulnerability leading to invalid memory access.
5
Can CVE-2017-15932 be exploited remotely?
Yes, CVE-2017-15932 can potentially be exploited by an attacker using crafted ELF files to trigger the vulnerability.