CVE-2017-6197: Null Pointer Dereference
Published Feb 24, 2017
·Updated
The rread functions in libr/include/rendian.h in radare2 1.2.1 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by the rreadle32 function.
Affected Software
1 affected component
Radare Radare2=1.2.1
Remediation
Patch Available
Event History
Feb 24, 2017
CVE Published
via MITRE·04:23 AM
Data Sourced
via MITRE·04:23 AM
Description
Data Sourced
via NVD·04:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6197?
The severity of CVE-2017-6197 is considered medium due to the potential for denial of service.
2
How do I fix CVE-2017-6197?
To fix CVE-2017-6197, update to a version of radare2 that is patched against this vulnerability.
3
What causes the vulnerability identified as CVE-2017-6197?
CVE-2017-6197 is caused by a NULL pointer dereference in the r_read_* functions while processing crafted binary files.
4
Which versions of radare2 are affected by CVE-2017-6197?
Radare2 version 1.2.1 is affected by CVE-2017-6197.
5
Can CVE-2017-6197 be exploited remotely?
Yes, CVE-2017-6197 can be exploited remotely through crafted binary files.