First published: Fri Oct 27 2017(Updated: )
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
radare2 | =2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15932 has a moderate severity due to potential integrity issues caused by invalid memory access.
To fix CVE-2017-15932, update radare2 to the latest version that contains the patch for this vulnerability.
CVE-2017-15932 specifically affects radare2 version 2.0.1 running on 32-bit systems.
CVE-2017-15932 is categorized as an integer exception vulnerability leading to invalid memory access.
Yes, CVE-2017-15932 can potentially be exploited by an attacker using crafted ELF files to trigger the vulnerability.