CVE-2017-16359: Null Pointer Dereference
Published Nov 1, 2017
·Updated
In radare 2.0.1, a pointer wraparound vulnerability exists in storeversioninfognuverdef() in libr/bin/format/elf/elf.c.
Affected Software
1 affected component
Radare Radare2=2.0.1
Remediation
Patch Available
Event History
Nov 1, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16359?
CVE-2017-16359 has been classified with medium severity due to its potential to lead to undefined behavior in the affected software.
2
How do I fix CVE-2017-16359?
To remediate CVE-2017-16359, upgrade radare2 to version 2.0.2 or later as it includes fixes for this vulnerability.
3
What versions of radare2 are affected by CVE-2017-16359?
CVE-2017-16359 specifically affects version 2.0.1 of radare2.
4
Can CVE-2017-16359 be exploited remotely?
CVE-2017-16359 does not typically allow for remote exploitation as it primarily affects local interactions with the software.
5
What type of vulnerability is CVE-2017-16359?
CVE-2017-16359 is categorized as a pointer wraparound vulnerability in the ELF format handling in radare2.